PT-2023-1501 · Fortinet · Fortigate+2
Published
2023-02-16
·
Updated
2023-07-18
·
CVE-2022-22302
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiGate versions 6.0.0 through 6.0.13
FortiGate versions 6.2.0 through 6.2.9
FortiGate versions 6.4.0 through 6.4.1
FortiAuthenticator version 5.5.0
FortiAuthenticator versions 6.0
FortiAuthenticator versions 6.1
Description
A clear text storage of sensitive information vulnerability may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem. The potentially exposed private keys have been revoked.
Recommendations
For FortiGate versions 6.0.0 through 6.0.13, upgrade to a newer version that contains a fix for this issue.
For FortiGate versions 6.2.0 through 6.2.9, upgrade to a newer version that contains a fix for this issue.
For FortiGate versions 6.4.0 through 6.4.1, upgrade to a newer version that contains a fix for this issue.
For FortiAuthenticator version 5.5.0, upgrade to a newer version that contains a fix for this issue.
For FortiAuthenticator versions 6.0, upgrade to a newer version that contains a fix for this issue.
For FortiAuthenticator versions 6.1, upgrade to a newer version that contains a fix for this issue.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiauthenticator
Fortigate
Fortios