QID 44097
Date Published: 2023-08-09
QID 44097: FortiOS - Buffer Overflow Vulnerability (FG-IR-20-083)
FortiOS is vulnerable to a stack-based buffer overflow in FortiGate.
Affected Versions:
FortiOS Versions 5.6.12 and below
FortiOS Versions 6.0.10 and below
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful attack may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-20-083
Vendor References
- FG-IR-20-083 -
www.fortiguard.com/psirt/FG-IR-20-083
CVEs related to QID 44097
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-20-083 |
|