CVE-2022-29060

HIGH

FortiDDoS API <5.5.1 - Code Injection

Title source: llm
STIX 2.1

Description

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-22-071

Scores

CVSS v3 8.1
EPSS 0.0046
EPSS Percentile 64.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (9)
fortinet/fortiddos 5.1.0
fortinet/fortiddos 5.2.0
fortinet/fortiddos 5.3.0
fortinet/fortiddos 5.3.1
fortinet/fortiddos 5.4.0
fortinet/fortiddos 5.4.1
fortinet/fortiddos 5.4.2
fortinet/fortiddos 5.5.0
fortinet/fortiddos 5.5.1
Published Jul 19, 2022
Tracked Since Feb 18, 2026