High severity8.1NVD Advisory· Published Jul 19, 2022· Updated Jun 17, 2026
CVE-2022-29060
CVE-2022-29060
Description
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
Affected products
11cpe:2.3:a:fortinet:fortiddos:5.1.0:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:fortinet:fortiddos:5.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiddos:5.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiddos:5.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiddos:5.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiddos:5.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiddos:5.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiddos:5.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiddos:5.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiddos:5.5.1:*:*:*:*:*:*:*
- Range: 5.5.0-5.5.1, 5.4.0-5.4.2, 5.3.0-5.3.1, 5.2.0, 5.1.0
- Range: FortiDDoS 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-071nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.