QID 44088

Date Published: 2023-07-14

QID 44088: Fortinet FortiOS Denial of Service (DoS) Vulnerability (FG-IR-19-013)

An Uncontrolled Resource Consumption vulnerability in multiple products may allow an attacker to cause web service portal denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly. Affected Versions:
FortiOS versions 6.2.2 and below

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Note: Making this QID practice as this QID also contains banner based detection .

An Uncontrolled Resource Consumption vulnerability in multiple products may allow an attacker to cause web service portal denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-19-013
    Vendor References

    CVEs related to QID 44088

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-19-013 URL Logo www.fortiguard.com/psirt/FG-IR-19-013