Cleartext storage of sensitive information in FortiAuthenticator and FortiOS - CVE-2022-22302

 

Cleartext storage of sensitive information in FortiAuthenticator and FortiOS - CVE-2022-22302

Published: February 17, 2023


Vulnerability identifier: #VU72351
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22302
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to unprotected storage of keys used for authentication. A local user can retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services.


Affected software

FortiAuthenticator
FortiOS

How to mitigate CVE-2022-22302

Install updates from vendor's website.

FortiAuthenticator - addressed in versions 6.0.5, 6.1.1, 6.2.0
FortiOS - addressed in versions 6.0.14, 6.2.10, 6.4.2

External References

Related Security Bulletins