QID 44173
Date Published: 2024-02-26
QID 44173: FortiOS Rapid Reset HTTP/2 Vulnerability (FG-IR-23-397)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly.
Affected Versions:
FortiOS 7.4 versions 7.4.0 through 7.4.1
FortiOS 7.2 versions 7.2.0 through 7.2.6
FortiOS 7.0 versions 7.0.0 through 7.0.13
QID Detection Logic (Authenticated):(LINUX)
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-23-397
Workaround:
The vendor advised to remove HTTP/2 support with proxy mode with SSL inspection here.
- FG-IR-23-397 -
www.fortiguard.com/psirt/FG-IR-23-397
CVEs related to QID 44173
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-397 |
|