CVE-2022-30307Fortinet Fortios vulnerability

4 documents4 sources
Severity
8.1HIGHNVD
CNA3.9
EPSS
1.0%
top 23.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2

Description

A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortios6.4.06.4.10+2
CVEListV5fortinet/fortinet_fortiosFortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mjqc-2998-5j3f: A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 72022-11-02
CVEList
CVE-2022-30307: A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 72022-11-02

📋Vendor Advisories

1
Fortinet
RSA SSH host key lost at shutdown2022-11-02
CVE-2022-30307 — Fortinet Fortios vulnerability | cvebase