Insecure RSA key transport

Summary

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors.

Affected Products

FortiEDR version 5.0.0 through 5.0.2
FortiEDR 4.0 all versions

Solutions

Upgrade to FortiEDR version 5.0.3.

Acknowledgement

Internally discovered and reported by Giuseppe Cocomazzi of Fortinet Product Security team.

Timeline

2022-04-05: Initial publication