QID 44141

Date Published: 2023-12-21

QID 44141: FortiOS Null Pointer Dereference Vulnerability (FG-IR-23-151)

A null pointer dereference in FortiOS may allow an authenticated attacker to perform a DoS attack on the device via specifically crafted HTTP requests.

Affected Versions:
FortiOS version 7.4.0
FortiOS versions 7.2.0 through 7.2.5
FortiOS versions 7.0.0 through 7.0.12
FortiOS 6.4 all versions
FortiOS 6.2 all versions
FortiOS 6.0 all versions

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.

Vulnerable version os FortiOS may allow an authenticated attacker to perform a DoS attack on the device via specifically crafted HTTP requests.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-23-151

    Vendor References

    CVEs related to QID 44141

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-151 URL Logo www.fortiguard.com/psirt/FG-IR-23-151