QID 44079
Date Published: 2023-07-14
QID 44079: FortiOS - Stack-based Buffer Overflow Vulnerability (FG-IR-19-248)
A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS may allow an authenticated remote attacker to crash the service by sending a malformed PUT request to the server
Affected Versions:
FortiOS versions 6.0.10 and below.
FortiOS versions 6.2.2 and below.
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Note: detection is practice as QID has banner based detection
Successful exploit may allow an authenticated remote attacker to crash the service
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-19-248
Vendor References
- FG-IR-19-248 -
www.fortiguard.com/psirt/FG-IR-19-248
CVEs related to QID 44079
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-19-248 |
|