CVE-2022-29053

LOW

FortiOS 7.2.0, 7.0.0-7.0.5 - Missing Cryptographic Steps in Keytab File Encryption

Title source: llm
STIX 2.1

Description

A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-22-158

Scores

CVSS v3 2.3
EPSS 0.0005
EPSS Percentile 15.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (2)
fortinet/fortios 7.2.0
fortinet/fortios 6.0.0 - 6.0.14
Published Sep 06, 2022
Tracked Since Feb 18, 2026