A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-071 | Patch Vendor Advisory |
https://fortiguard.com/psirt/FG-IR-22-071 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.com/psirt/FG-IR-22-071 - Patch, Vendor Advisory |
Information
Published : 2022-07-19 14:15
Updated : 2024-11-21 06:58
NVD link : CVE-2022-29060
Mitre link : CVE-2022-29060
CVE.ORG link : CVE-2022-29060
JSON object : View
Products Affected
fortinet
- fortiddos
CWE
CWE-798
Use of Hard-coded Credentials