CVE Vulnerabilities

CVE-2022-30307

Published: Nov 02, 2022 | Modified: Aug 08, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 6.4.0 (including) 6.4.10 (excluding)
Fortios Fortinet 7.0.1 (including) 7.0.8 (excluding)
Fortios Fortinet 7.2.0 (including) 7.2.2 (excluding)

References