Low severity3.3NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026
CVE-2022-29054
CVE-2022-29054
Description
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to decipher it.
Affected products
8cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.1.0,<=1.1.6
- cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
- (no CPE)range: 7.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-080nvdVendor Advisory
News mentions
0No linked articles in our index yet.