CVE-2022-30307: RSA SSH host key lost at shutdown
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.
Other sources
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS may allow an unauthenticated attacker to perform a man in the middle attack.
— FortiGuard
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-30307?
CVE-2022-30307 is a key management error vulnerability affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below.
How does CVE-2022-30307 impact my system?
CVE-2022-30307 may allow an unauthenticated attacker to perform a man-in-the-middle attack.
What is the severity of CVE-2022-30307?
CVE-2022-30307 has a severity rating of high (8.1).
How can I fix CVE-2022-30307?
To fix CVE-2022-30307, update your FortiOS to version 6.4.10 or above, 7.0.8 or above, or 7.2.2 or above.
Where can I find more information about CVE-2022-30307?
You can find more information about CVE-2022-30307 at the FortiGuard PSIRT advisory: [link](https://fortiguard.com/psirt/FG-IR-22-228).