Use of Hard-Coded Cryptographic Key in Fortinet FortiEDR Collectors
CVE-2022-23440

7.8HIGH

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
6 April 2022

What is CVE-2022-23440?

A vulnerability exists in the registration mechanism of FortiEDR collectors that employs hard-coded cryptographic keys. This flaw may enable a local attacker to bypass security measures, potentially allowing them to disable and uninstall the collectors from the endpoints in the same deployment. Proper security protocols and configurations are paramount to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Fortinet FortiEDR FortiEDR 5.0.2, 5.0.1, 5.0.0, 4.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.