QID 44073

Date Published: 2023-06-27

QID 44073: Fortinet FortiOS Denial of Service (DoS) Vulnerability (FG-IR-23-015)

A NULL pointer dereference vulnerability [CWE-476] in SSL-VPN may allow an authenticated remote attacker to trigger a crash of the SSL-VPN service via crafted requests.

Affected Versions:
FortiOS version 7.2.0 through 7.2.4
FortiOS version 7.0.0 through 7.0.10
FortiOS version 6.4.0 through 6.4.12

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Note: Making this QID practice as this QID also contains banner based detection .

Successful exploitation of the vulnerability may allow authenticated remote attacker to perform a NULL pointer dereference vulnerability attack

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-23-015
    Vendor References

    CVEs related to QID 44073

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-015 URL Logo www.fortiguard.com/psirt/FG-IR-23-015