VYPR
Low severity3.9NVD Advisory· Published Nov 2, 2022· Updated Jun 17, 2026

CVE-2022-30307

CVE-2022-30307

Description

A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack.

Affected products

3
  • Fortinet/Fortios2 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.4.0,<6.4.10
    • (no CPE)range: <=7.2.0, <=7.0.6, <=6.4.9
  • Fortinet/Fortinetcpe-rescue
    Range: FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.