QID 44144
Date Published: 2024-01-16
QID 44144: FortiOS Denial of Service (DoS) Vulnerability (FG-IR-19-236)
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS and FortiProxy may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.
Affected Versions:
FortiOS versions 6.2.1 and below
FortiOS versions 6.0.6 and below
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Successful exploit may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-19-236
Vendor References
- FG-IR-19-236 -
www.fortiguard.com/psirt/FG-IR-19-236
CVEs related to QID 44144
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-19-236 |
|