CVE-2022-30307

LOW

FortiOS <7.2.0-6.4.9 - Man in the Middle

Title source: llm
STIX 2.1

Description

A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.

References (1)

Core 1
Core References

Scores

CVSS v3 3.9
EPSS 0.0097
EPSS Percentile 76.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
fortinet/fortios 6.4.0 - 6.4.10
Published Nov 02, 2022
Tracked Since Feb 18, 2026