CVE-2022-29054
16.02.2023, 19:15
A missing cryptographic steps vulnerability [CWE-325]in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow anattacker inpossession of the encrypted key to decipher it.Enginsight
Vendor | Product | Version |
---|---|---|
fortinet | fortiproxy | 1.1.0 ≤ 𝑥 ≤ 1.1.6 |
fortinet | fortiproxy | 1.2.0 ≤ 𝑥 ≤ 1.2.13 |
fortinet | fortiproxy | 2.0.0 ≤ 𝑥 ≤ 2.0.11 |
fortinet | fortiproxy | 7.0.0 ≤ 𝑥 < 7.0.8 |
fortinet | fortiproxy | 7.2.0 |
fortinet | fortiproxy | 7.2.1 |
fortinet | fortios | 6.0.0 ≤ 𝑥 ≤ 6.0.16 |
fortinet | fortios | 6.2.0 ≤ 𝑥 ≤ 6.2.12 |
fortinet | fortios | 6.4.0 ≤ 𝑥 ≤ 6.4.11 |
fortinet | fortios | 7.0.0 ≤ 𝑥 < 7.0.8 |
fortinet | fortios | 7.2.0 |
𝑥
= Vulnerable software versions