QID 44143
QID 44143: FortiOS Denial of Service (DoS) Vulnerability (FG-IR-14-006)
A temporary denial of service condition can be created using a specially crafted request sent to the FortiManager protocol service in FortiOS version 5.0.0 to 5.0.7 and FortiOS version 4.3.15 and lower. Code execution has not been demonstrated, but may be possible under certain conditions.
Affected Versions:
FortiOS 5.0.0 to 5.0.7
FortiOS 4.3.15 and lower
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Successful exploit may allow an remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted request.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-14-006
Workaround:
These vulnerabilities can also be mitigated by disabling FGFM-Access on the interface, or blocking traffic for TCP port 541 with a local-in policy.
- FG-IR-14-006 -
www.fortiguard.com/psirt/FG-IR-14-006
CVEs related to QID 44143
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-14-006 |
|