QID 44089
Date Published: 2023-07-14
QID 44089: FortiOS - Traffic Bypass Vulnerability (FG-IR-20-172)
FortiOS is vulnerable to a traffic bypass vulnerability.
Affected Versions:
FortiOS versions 6.4.2 and below
FortiOS versions 6.2.5 and below
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
NOTE: As we do not check for the workaround, kept the QID as Practice.
Vulnerable versions of FortiOS may allow malicious traffic to bypass the transparent proxy policy when traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiOS on port 80/443 that would lack a valid HTTP header.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-20-172Workaround:
Workaround is to disable tunnel-non-http and block unsupported-ssl.
Workaround is to disable tunnel-non-http and block unsupported-ssl.
Vendor References
- FG-IR-20-172 -
www.fortiguard.com/psirt/FG-IR-20-172
CVEs related to QID 44089
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-172 |
|