---
cve: "CVE-2022-45858"
severity: "LOW"
cvss: 3.8
epss: "20%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2023-05-03 22:15:15"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T01:18:02+02:00"
---

# CVE-2022-45858

> 3.8 LOW

## Beschreibung

A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions, 8.7.0 all versions may increase the chances of an attacker to have access to sensitive information or to perform man-in-the-middle attacks.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:P/RL:U/RC:R
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-327** — Use of a Broken or Risky Cryptographic Algorithm
  The product uses a broken or risky cryptographic algorithm or protocol.

## Angriffsmuster (CAPEC)

- [CAPEC-20 — Encryption Brute Forcing](https://capec.mitre.org/data/definitions/20.html) _(Severity: Low)_
- [CAPEC-97 — Cryptanalysis](https://capec.mitre.org/data/definitions/97.html) _(Severity: Very High)_
- [CAPEC-459 — Creating a Rogue Certification Authority Certificate](https://capec.mitre.org/data/definitions/459.html) _(Severity: Very High)_
- [CAPEC-473 — Signature Spoof](https://capec.mitre.org/data/definitions/473.html)
- [CAPEC-475 — Signature Spoofing by Improper Validation](https://capec.mitre.org/data/definitions/475.html) _(Severity: High)_
- [CAPEC-608 — Cryptanalysis of Cellular Encryption](https://capec.mitre.org/data/definitions/608.html) _(Severity: High)_
- [CAPEC-614 — Rooting SIM Cards](https://capec.mitre.org/data/definitions/614.html) _(Severity: High)_

## ATT&CK-Techniken

- [T1036.001 — Masquerading: Invalid Code Signature](https://attack.mitre.org/techniques/T1036/001/)
- [T1553.002 — Subvert Trust Controls: Code Signing](https://attack.mitre.org/techniques/T1553/002/)

## Referenzen

- <https://fortiguard.com/psirt/FG-IR-22-452>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2022-45858) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
