QID 43912
Date Published: 2022-10-18
QID 43912: FortiOS Heap-based Buffer Overflow Vulnerability (FG-IR-21-115)
A heap-based buffer overflow [CWE-122] in the firmware signature verification function of FortiOS may allow an attacker to execute arbitrary code via specially crafted installation images.
Affected Products:
FortiGate E-series and F-series models released in 2019 and later (specifically: 40F, 60F, 200F, 400E, 600E, 1100E, 1800F, 2200E, 2600F, 3300E, 3400E, 3500F, 3600E and 7121F) that are running the following versions of FortiOS:
FortiOS version 7.0.1 and below
FortiOS version 6.4.6 and below
FortiOS version 6.2.9 and below
FortiOS version 6.0.13 and below
FortiOS-6K7K version 6.4.2 and below
FortiOS-6K7K version 6.2.7 and below
FortiOS-6K7K version 6.0.10 and below
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Note: Detection is made potential because the signature doesn't differentiate FortiGate E-series and F-series models and their versions.
Vulnerable version of FortiOS may allow an attacker to execute arbitrary code via specially crafted installation images.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-115
- FG-IR-21-115 -
www.fortiguard.com/psirt/FG-IR-21-115
CVEs related to QID 43912
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-115 |
|