QID 43990

Date Published: 2023-03-09

QID 43990: FortiOS Heap Buffer Underflow Vulnerability (FG-IR-23-001)

A buffer underwrite buffer underflow vulnerability in FortiOS and FortiProxy administrative interface may allow a remote unauthenticated attacker to execute arbitrary code on the device and perform a DoS on the GUI

Making this QID as practice as we cannot add HTTP/HTTPS disable status check in signature.

Affected Versions:
FortiOS version 7.2.0 through 7.2.3 FortiOS version 7.0.0 through 7.0.9 FortiOS version 6.4.0 through 6.4.11 FortiOS version 6.2.0 through 6.2.12 FortiOS 6.0 all versions

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Successful exploitation of the vulnerability may allow an remote unauthenticated attacker to execute arbitrary code on the device and/or perform a DoS on the GUI, via specifically crafted requests.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-23-001
    Vendor References

    CVEs related to QID 43990

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-001 URL Logo www.fortiguard.com/psirt/FG-IR-23-001