QID 43944
Date Published: 2022-12-14
QID 43944: FortiOS Buffer OverFlow Vulnerability (FG-IR-22-398)
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Affected Versions:
FortiOS version 7.2.0 through 7.2.2
FortiOS version 7.0.0 through 7.0.8
FortiOS version 6.4.0 through 6.4.10
FortiOS version 6.2.0 through 6.2.11
FortiOS version 6.0.0 through 6.0.15
FortiOS version 5.6.0 through 5.6.14
FortiOS version 5.4.0 through 5.4.13
FortiOS version 5.2.0 through 5.2.15
FortiOS version 5.0.0 through 5.0.14
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow remote code execution.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-398Workaround:
Vendor has recommended to disable SSL-VPN as a workaround for the vulnerability.
Vendor has recommended to disable SSL-VPN as a workaround for the vulnerability.
Vendor References
- FG-IR-22-398 -
www.fortiguard.com/psirt/FG-IR-22-398
CVEs related to QID 43944
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-398 |
|