QID 44085

Date Published: 2023-07-14

QID 44085: FortiOS - Buffer Underwrite in firmware verification Vulnerability (FG-IR-21-046)

A buffer underwrite (CWE-124) vulnerability in the firmware verification routine of FortiOS,

Affected Versions:
FortiOS version 7.0.0
FortiOS version 6.4.0 through 6.4.6
FortiOS version 6.2.0 through 6.2.9
FortiOS version 6.0.0 through 6.0.13
FortiOS 5.6 all versions
FortiOS 5.4 all versions
FortiOS 5.2 all versions
FortiOS 5.0 all versions

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Vulnerable versions of FortiOS may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image.P>

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-21-046
    Vendor References

    CVEs related to QID 44085

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-046 URL Logo www.fortiguard.com/psirt/FG-IR-21-046