CVE-2022-29054
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to decipher it.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:X
- EPSS probability
- 0.08%
- CWE
- CWE-329
- Published
- 2023-02-16
- Last modified
- 2026-03-13
Affected products
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiProxy
- Fortinet FortiProxy
- Fortinet FortiProxy
Weakness type
Related vulnerabilities
- CVE-2026-14969 — 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption
- CVE-2024-56141 — Minosoft has IV equal to key
- CVE-2026-45787 — electerm's encrypt method not safe enough
- CVE-2024-49783 — IBM OpenPages with Watson information disclosure
- CVE-2025-2814 — Crypt::CBC versions between 1.21 and 3.05 for Perl may use insecure rand() function for cryptographic functions
- CVE-2021-27499 — Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2,...
- CVE-2020-5408 — Dictionary attack with Spring Security queryable text encryptor
- CVE-2017-3226 — Das U-Boot's AES-CBC encryption feature improperly handles an error condition and may allow attacks against the underlying cryptographic implementation and allow an attacker to decrypt the data