Use of Hard-Coded Cryptographic Key in Fortinet FortiEDR Collectors
CVE-2022-23440

7.8HIGH

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
6 April 2022

Summary

A vulnerability exists in the registration mechanism of FortiEDR collectors that employs hard-coded cryptographic keys. This flaw may enable a local attacker to bypass security measures, potentially allowing them to disable and uninstall the collectors from the endpoints in the same deployment. Proper security protocols and configurations are paramount to mitigate the risks associated with this vulnerability.

Affected Version(s)

Fortinet FortiEDR FortiEDR 5.0.2, 5.0.1, 5.0.0, 4.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.