CVE-2022-29054

A missing cryptographic steps vulnerability [CWE-325]in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow anattacker inpossession of the encrypted key to decipher it.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
fortinetCNA
3.1 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:X
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
VendorProductVersion
fortinetfortiproxy
1.1.0 ≤
𝑥
≤ 1.1.6
fortinetfortiproxy
1.2.0 ≤
𝑥
≤ 1.2.13
fortinetfortiproxy
2.0.0 ≤
𝑥
≤ 2.0.11
fortinetfortiproxy
7.0.0 ≤
𝑥
< 7.0.8
fortinetfortiproxy
7.2.0
fortinetfortiproxy
7.2.1
fortinetfortios
6.0.0 ≤
𝑥
≤ 6.0.16
fortinetfortios
6.2.0 ≤
𝑥
≤ 6.2.12
fortinetfortios
6.4.0 ≤
𝑥
≤ 6.4.11
fortinetfortios
7.0.0 ≤
𝑥
< 7.0.8
fortinetfortios
7.2.0
𝑥
= Vulnerable software versions