QID 44066
Date Published: 2023-06-21
QID 44066: Fortinet FortiOS Denial of Service (DoS) Vulnerability (FG-IR-23-095)
An access of uninitialized pointer vulnerability [CWE-824] in FortiOS administrative interface API may allow an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests.
Affected Versions:
FortiOS version 7.2.0 through 7.2.4
FortiOS version 7.0.0 through 7.0.11
FortiOS 6.4 all versions
FortiOS 6.2 all versions
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Note: Making this QID practice as this QID also contains banner based detection .
Successful exploitation of the vulnerability may allow an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-23-095
Vendor References
- FG-IR-23-095 -
www.fortiguard.com/psirt/FG-IR-23-095
CVEs related to QID 44066
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-095 |
|