QID 44080
Date Published: 2023-07-14
QID 44080: FortiOS - Denial of Service (DoS) Vulnerability (FG-IR-20-082)
A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiOS may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet, when tunnel mode is enabled.
Affected Versions:
FortiOS versions 5.6.12 and below.
FortiOS versions 6.0.10 and below.
FortiOS versions 6.2.4 and below.
FortiOS versions 6.4.1 and below.
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation may lead to denial of service
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-20-082
Vendor References
- FG-IR-20-082 -
www.fortiguard.com/psirt/FG-IR-20-082
CVEs related to QID 44080
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-082 |
|