QID 44075

Date Published: 2023-07-14

QID 44075: FortiOS - Denial of Service (DoS) Vulnerability in firmware upgrade function (FG-IR-22-375)

A loop with unreachable exit condition ('Infinite Loop') vulnerability [CWE-835] in FortiOS may allow an authenticated attacker to perform a denial of service via a specially crafted firmware image.

Affected Versions:
FortiOS version 7.2.0 through 7.2.4
FortiOS version 7.0.0 through 7.0.10
FortiOS 6.4 all versions
FortiOS 6.2 all versions
FortiOS 6.0 all versions

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Note: Making this QID practice as this QID also contains banner based detection .

Successful exploitation of the vulnerability may allow an authenticated attacker to perform a denial of service via a specially crafted firmware image.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-375
    Vendor References

    CVEs related to QID 44075

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-375 URL Logo www.fortiguard.com/psirt/FG-IR-22-375