FORTINET Security Advisory

Published Date: Not specified

CVE: CVE-2022-0778

Advisory Summary

๐Ÿ”ถ Vulnerability & Market Signal (DoS risk in OpenSSL parsing)
Fortinet PSIRT disclosed CVE-2022-0778 (CVSSv3 7.5), impacting OpenSSL versions used in some Fortinet products. The issue is an infinite loop in BNmodsqrt() when processing modular square roots for certain non-prime moduli.

โš ๏ธ Why this matters in data center & infrastructure environments
This creates a practical DoS vector against systems that accept externally provided certificates/keysโ€”relevant to: load balancers, reverse proxies, PKI workflows, hosting platforms that ingest customer certificates, and TLS termination services. Even if the certificate signature is later rejected, the device may still be forced into an infinite loop during parsing.

๐Ÿ“Œ
-2022-0778

Reference: Vendor Advisory