CVE-2022-29054: Flaws over DHCP and DNS keys encryption scheme
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys (ddns-key or n-mhae-key) in FortiOS & FortiProxy configuration may allow an attacker in possession of the encrypted key to decipher it.
Other sources
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to decipher it.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-29054.
What is the severity level of CVE-2022-29054?
The severity level of CVE-2022-29054 is low.
Which software versions are affected by CVE-2022-29054?
Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x, and 6.0.x are affected by CVE-2022-29054.
What is the CWE category of CVE-2022-29054?
The CWE category of CVE-2022-29054 is CWE-325 (Missing Cryptographic Step).
How can an attacker exploit CVE-2022-29054?
An attacker in possession of the encrypted key can decipher it to exploit CVE-2022-29054.