CVE-2022-29060

EUVD-2022-33473
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:U/RC:R
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
fortinetfortiddos
5.1.0
fortinetfortiddos
5.2.0
fortinetfortiddos
5.3.0
fortinetfortiddos
5.3.1
fortinetfortiddos
5.4.0
fortinetfortiddos
5.4.1
fortinetfortiddos
5.4.2
fortinetfortiddos
5.5.0
fortinetfortiddos
5.5.1
𝑥
= Vulnerable software versions