QID 44085
Date Published: 2023-07-14
QID 44085: FortiOS - Buffer Underwrite in firmware verification Vulnerability (FG-IR-21-046)
A buffer underwrite (CWE-124) vulnerability in the firmware verification routine of FortiOS,
Affected Versions:
FortiOS version 7.0.0
FortiOS version 6.4.0 through 6.4.6
FortiOS version 6.2.0 through 6.2.9
FortiOS version 6.0.0 through 6.0.13
FortiOS 5.6 all versions
FortiOS 5.4 all versions
FortiOS 5.2 all versions
FortiOS 5.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable versions of FortiOS may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image.P>
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-21-046
Vendor References
- FG-IR-21-046 -
www.fortiguard.com/psirt/FG-IR-21-046
CVEs related to QID 44085
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-046 |
|