Key Management Error in FortiOS by Fortinet
CVE-2022-30307

3.9LOW

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
2 November 2022

Summary

FortiOS, the operating system for Fortinet's security appliances, is susceptible to a key management error that impacts the RSA SSH host key. This vulnerability may enable unauthenticated attackers to execute man-in-the-middle attacks, compromising secure communications. Users are advised to update to the latest versions to mitigate this risk.

Affected Version(s)

Fortinet FortiOS FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.