QID 43932
Date Published: 2022-11-14
QID 43932: FortiOS - Access to NULL Pointer Vulnerability in Secure Sockets Layer (SSL) Virtual Private Network (VPN) Portal (FG-IR-22-086)
An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of FortiOS may allow a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
Affected Products:
No need to be authenticated to provoke a crash:
FortiOS version 6.4.4 through 6.4.9
FortiOS version 7.0.0 through 7.0.5
FortiOS version 7.2.0
Need to be authenticated to provoke a crash:
FortiOS 6.0 all versions
FortiOS version 6.2.0 through 6.2.10
FortiOS version 6.4.0 through 6.4.3
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable version may allow a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via HTTP GET request
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-086
- FG-IR-22-086 -
www.fortiguard.com/psirt/FG-IR-22-086
CVEs related to QID 43932
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-086 |
|