imPC@ndo IT

Tracker / CVE-2022-22302

CVE-2022-22302

Medium 5.3

A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem.

Affected products and versions

fortinet fortiauthenticator
fortinet fortiauthenticator · 6.0.0 → 6.0.4
fortinet fortios
fortinet fortios · 6.0.0 → 6.0.13
fortinet fortios · 6.2.0 → 6.2.9

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References