CVE-2022-22302: Cert private key disclosure
A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate and FortiAuthenticator may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem.
The potentially exposed private keys have been revoked, please upgrade to the versions provided in the solutions to support push proxy.
Other sources
A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22302.
What is the severity rating of CVE-2022-22302?
CVE-2022-22302 has a severity rating of medium.
Which software versions are affected by CVE-2022-22302?
CVE-2022-22302 affects FortiGate versions 6.4.0 through 6.4.1, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13, as well as FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-312.
How can a local unauthorized party exploit this vulnerability?
A local unauthorized party may exploit CVE-2022-22302 to retrieve the Fortinet private information stored in clear text.