CVE Vulnerabilities

CVE-2022-22302

Cleartext Storage of Sensitive Information

Published: Jul 11, 2023 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

NameVendorStart VersionEnd Version
FortiauthenticatorFortinet6.0.0 (including)6.0.4 (including)
FortiauthenticatorFortinet5.5.0 (including)5.5.0 (including)
FortiauthenticatorFortinet6.1.0 (including)6.1.0 (including)
FortiosFortinet6.0.0 (including)6.0.13 (including)
FortiosFortinet6.2.0 (including)6.2.9 (including)
FortiosFortinet6.4.0 (including)6.4.0 (including)
FortiosFortinet6.4.1 (including)6.4.1 (including)

Potential Mitigations

References