FG-IR-22-080: Flaws over DHCP and DNS keys encryption scheme
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys (ddns-key or n-mhae-key) in FortiOS & FortiProxy configuration may allow an attacker in possession of the encrypted key to decipher it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-22-080?
The severity of FG-IR-22-080 is high due to the potential exposure of sensitive encrypted keys.
How do I fix FG-IR-22-080?
To fix FG-IR-22-080, update to the latest version of FortiOS or FortiProxy that addresses this cryptographic vulnerability.
What systems are affected by FG-IR-22-080?
FG-IR-22-080 affects Fortinet FortiOS and FortiProxy configurations that utilize DDNS or n-mhae keys.
What is the nature of the vulnerability in FG-IR-22-080?
FG-IR-22-080 is a missing cryptographic steps vulnerability that allows an attacker to decipher encrypted keys.
What can an attacker do if they exploit FG-IR-22-080?
If exploited, an attacker can potentially access sensitive information by deciphering the encrypted DHCP and DNS keys.