QID 43912

Date Published: 2022-10-18

QID 43912: FortiOS Heap-based Buffer Overflow Vulnerability (FG-IR-21-115)

A heap-based buffer overflow [CWE-122] in the firmware signature verification function of FortiOS may allow an attacker to execute arbitrary code via specially crafted installation images.

Affected Products:
FortiGate E-series and F-series models released in 2019 and later (specifically: 40F, 60F, 200F, 400E, 600E, 1100E, 1800F, 2200E, 2600F, 3300E, 3400E, 3500F, 3600E and 7121F) that are running the following versions of FortiOS:
FortiOS version 7.0.1 and below
FortiOS version 6.4.6 and below
FortiOS version 6.2.9 and below
FortiOS version 6.0.13 and below
FortiOS-6K7K version 6.4.2 and below
FortiOS-6K7K version 6.2.7 and below
FortiOS-6K7K version 6.0.10 and below

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Note: Detection is made potential because the signature doesn't differentiate FortiGate E-series and F-series models and their versions.

Vulnerable version of FortiOS may allow an attacker to execute arbitrary code via specially crafted installation images.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-21-115

    Vendor References

    CVEs related to QID 43912

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-115 URL Logo www.fortiguard.com/psirt/FG-IR-21-115