CVE-2022-30307
published 2022-11-02CVE-2022-30307: A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an…
PriorityP343high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.44%
35.7th percentile
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet_fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.0 < 6.4.10 | 6.4.10 |
| fortinet | fortios | >= 7.0.1 < 7.0.8 | 7.0.8 |
| fortinet | fortios | >= 7.2.0 < 7.2.2 | 7.2.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mjqc-2998-5j3f: A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7
ghsa_unreviewed·2022-11-02
CVE-2022-30307 [HIGH] GHSA-mjqc-2998-5j3f: A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.
Fortinet
RSA SSH host key lost at shutdown
vendor_fortinet·2022-11-02·CVSS 3.9
CVE-2022-30307 [LOW] RSA SSH host key lost at shutdown
FG-IR-22-228: RSA SSH host key lost at shutdown
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.
CVEs: CVE-2022-30307
CVSS: 3.9 (low)
Affected products: FortiOS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-02
Published