First published: Tue Nov 01 2022(Updated: )
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS may allow an unauthenticated attacker to perform a man in the middle attack.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-22-228 is typically classified as critical due to its potential for exploitation in man-in-the-middle attacks.
To fix FG-IR-22-228, ensure that you update your FortiOS to the latest version that addresses the key management error vulnerability.
Organizations using FortiOS that rely on RSA SSH host keys are susceptible to FG-IR-22-228.
FG-IR-22-228 allows unauthenticated attackers to perform man-in-the-middle attacks due to a key management error.
FG-IR-22-228 does not have a linked CVE ID, but it falls under the Common Weakness Enumeration category CWE-320.