A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-071 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-07-19 07:15
Updated : 2022-07-27 05:50
NVD link : CVE-2022-29060
Mitre link : CVE-2022-29060
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
fortinet
- fortiddos