QID 44173

Date Published: 2024-02-26

QID 44173: FortiOS Rapid Reset HTTP/2 Vulnerability (FG-IR-23-397)

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly.

Affected Versions:
FortiOS 7.4 versions 7.4.0 through 7.4.1
FortiOS 7.2 versions 7.2.0 through 7.2.6
FortiOS 7.0 versions 7.0.0 through 7.0.13

QID Detection Logic (Authenticated):(LINUX)
Detection checks for vulnerable version of FortiOS.

QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-23-397

    Workaround:
    The vendor advised to remove HTTP/2 support with proxy mode with SSL inspection here.

    Vendor References

    CVEs related to QID 44173

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-397 URL Logo www.fortiguard.com/psirt/FG-IR-23-397