A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://fortiguard.com/psirt/FG-IR-22-071 | vendor advisory patch |