QID 43947
Date Published: 2023-02-09
QID 43947: FortiOS - Rivest-Shamir-Adleman (RSA) SSH Host Key Lost At Shutdown Vulnerability (FG-IR-22-228)
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS may allow an unauthenticated attacker to perform a man in the middle attack.
Affected Versions:
FortiOS version 7.2.0
FortiOS version 7.0.1 through 7.0.6
FortiOS version 6.4.0 through 6.4.9
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow key management error vulnerability.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-228
Vendor References
- FG-IR-22-228 -
www.fortiguard.com/psirt/FG-IR-22-228
CVEs related to QID 43947
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-228 |
|