A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
References
Link | Resource |
---|---|
https://fortiguard.com/psirt/FG-IR-22-071 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2022-07-19 14:15
Updated : 2024-02-28 19:29
NVD link : CVE-2022-29060
Mitre link : CVE-2022-29060
CVE.ORG link : CVE-2022-29060
JSON object : View
Products Affected
fortinet
- fortiddos
CWE
CWE-798
Use of Hard-coded Credentials