Lucene search

K
fortinetFortiGuard LabsFG-IR-22-071
HistoryJun 07, 2022 - 12:00 a.m.

FortiDDoS - Use of hardcoded key for the JWT token

2022-06-0700:00:00
FortiGuard Labs
www.fortiguard.com
23
fortiddos
api
cryptographic key
jwt tokens
vulnerability
cwe-321
attacker
device

EPSS

0.002

Percentile

58.3%

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.

EPSS

0.002

Percentile

58.3%

Related for FG-IR-22-071