First published: Thu Feb 16 2023(Updated: )
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys (ddns-key or n-mhae-key) in FortiOS & FortiProxy configuration may allow an attacker in possession of the encrypted key to decipher it.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | ||
Fortinet FortiProxy |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-22-080 is high due to the potential exposure of sensitive encrypted keys.
To fix FG-IR-22-080, update to the latest version of FortiOS or FortiProxy that addresses this cryptographic vulnerability.
FG-IR-22-080 affects Fortinet FortiOS and FortiProxy configurations that utilize DDNS or n-mhae keys.
FG-IR-22-080 is a missing cryptographic steps vulnerability that allows an attacker to decipher encrypted keys.
If exploited, an attacker can potentially access sensitive information by deciphering the encrypted DHCP and DNS keys.