QID 43939

Date Published: 2022-11-03

QID 43939: FortiOS - Integer Overflow in dhcpd daemon Vulnerability (FG-IR-21-155)

An integer overflow / wraparound vulnerability [CWE-190] in the FortiOS, dhcpd daemon may allow an unauthenticated and network adjacent attacker to crash the dhcpd deamon, resulting in potential denial of service.

Affected Products:
FortiOS version 7.0.3 and below.
FortiOS version 6.4.8 and below.
FortiOS version 6.2.10 and below.
FortiOS version 6.0.x.

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Vulnerable version may allow an unauthenticated and network adjacent attacker to crash the dhcpd daemon, resulting in potential denial of service.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-21-155

    Vendor References

    CVEs related to QID 43939

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-155 URL Logo www.fortiguard.com/psirt/FG-IR-21-155