QID 44037
Date Published: 2023-05-31
QID 44037: FortiOS SSH Authentication Bypass Vulnerability (FG-IR-22-255) (Unauthenticated check)
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component may allow a remote and unauthenticated attacker to login into the device via sending specially crafted Access-Challenge response from the Radius server.
Affected Versions:
FortiOS version 7.2.0 through 7.2.1
FortiOS version 7.0.0 through 7.0.7
FortiOS version 6.4.0 through 6.4.9
FortiOS version 6.2 through 6.2.12
QID Detection Logic (UnAuthenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow Improper access control.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-255
Vendor References
- FG-IR-22-255 -
www.fortiguard.com/psirt/FG-IR-22-255
CVEs related to QID 44037
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-255 |
|