QID 43993

Date Published: 2023-03-21

QID 43993: Fortinet FortiOS Denial of Service (DoS) Vulnerability (FG-IR-22-477)

An access of uninitialized pointer vulnerability in the SSL-VPN portal of FortiOS may allow a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request. Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
FortiOS version 6.4.0 through 6.4.11
FortiOS 6.2 all versions

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Successful exploitation of the vulnerability may allow a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-477
    Vendor References

    CVEs related to QID 43993

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-477 URL Logo www.fortiguard.com/psirt/FG-IR-22-477