Rapid7

vulnerability

Fortinet FortiOS: Generation of Predictable IV with CBC Mode (CVE-2022-29054)

Severity
2
CVSS
(AV:L/AC:L/Au:S/C:P/I:N/A:N)
Published
Feb 16, 2023
Added
Feb 27, 2023
Modified
May 28, 2026

Description

A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to decipher it.

Solution

fortios-upgrade-7_0_8
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.