CVE Vulnerabilities

CVE-2022-22302

Cleartext Storage of Sensitive Information

Published: Jul 11, 2023 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Fortiauthenticator Fortinet 6.0.0 (including) 6.0.4 (including)
Fortiauthenticator Fortinet 5.5.0 (including) 5.5.0 (including)
Fortiauthenticator Fortinet 6.1.0 (including) 6.1.0 (including)
Fortios Fortinet 6.0.0 (including) 6.0.13 (including)
Fortios Fortinet 6.2.0 (including) 6.2.9 (including)
Fortios Fortinet 6.4.0 (including) 6.4.0 (including)
Fortios Fortinet 6.4.1 (including) 6.4.1 (including)

Potential Mitigations

References