QID 44139
Date Published: 2023-12-20
QID 44139: FortiOS Improper Access Control Vulnerability (FG-IR-23-432)
An improper access control vulnerability in FortiOS may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP database update.
Affected Versions:
FortiOS 7.2 versions prior to 7.2.1
FortiOS 7.0 all versions
FortiOS 6.4 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Vulnerable versions of FortiOS may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP database update.
Solution
Vendor has released fixes to address this vulnerability.
For more details, refer advisory FG-IR-23-432
For more details, refer advisory FG-IR-23-432
Vendor References
- FG-IR-23-432 -
www.fortiguard.com/psirt/FG-IR-23-432
CVEs related to QID 44139
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-432 |
|