QID 43976

Date Published: 2023-02-15

QID 43976: FortiOS - AV Engine - Evasion By Manipulating MIME Attachment Vulnerability (FG-IR-22-074)

An insufficient verification of data authenticity vulnerability FortiOS AV engines may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64. Affected Versions:
FortiOS version 6.0.0, 6.0.1, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.0.16, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.2.0, 6.2.1, 6.2.10, 6.2.11, 6.2.12, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.4.0, 6.4.1, 6.4.10, 6.4.11, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.2.0

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

NOTE: This QID is marked as practice as we are only checking FortiOS version.

Successful exploitation of the vulnerability may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-074
    Vendor References

    CVEs related to QID 43976

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-074 URL Logo www.fortiguard.com/psirt/FG-IR-22-074