VYPR
High severity8.1NVD Advisory· Published Jul 19, 2022· Updated Jun 17, 2026

CVE-2022-29060

CVE-2022-29060

Description

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.

Affected products

11
  • cpe:2.3:a:fortinet:fortiddos:5.1.0:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:fortinet:fortiddos:5.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiddos:5.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiddos:5.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiddos:5.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiddos:5.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiddos:5.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiddos:5.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiddos:5.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiddos:5.5.1:*:*:*:*:*:*:*
  • Range: 5.5.0-5.5.1, 5.4.0-5.4.2, 5.3.0-5.3.1, 5.2.0, 5.1.0
  • Range: FortiDDoS 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.