QID 44142
Date Published: 2023-12-20
QID 44142: FortiOS Root File System Bypass Vulnerability (FG-IR-22-396)
An improper validation of integrity check value vulnerability in FortiOS may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the file system integrity check in place.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.12
FortiOS 6.4 all versions
FortiOS 6.2 all versions
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Vulnerable version of FortiOS may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the file system integrity check in place.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-396
- FG-IR-22-396 -
www.fortiguard.com/psirt/FG-IR-22-396
CVEs related to QID 44142
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-396 |
|