QID 44176

Date Published: 2024-03-14

QID 44176: Fortinet FortiOS - Out-of-bounds Write in captive portal Execute unauthorized code or commands (FG-IR-23-328)

A security update for FortiOS has been released to fix the Execute unauthorized code or commands vulnerability. Affected Versions:
FortiOS version 7.4.0 through 7.4.1
FortiOS version 7.2.0 through 7.2.5
FortiOS version 7.0.0 through 7.0.12
FortiOS version 6.4.0 through 6.4.14
FortiOS version 6.2.0 through 6.2.15

QID Detection Logic (Authenticated):(LINUX)
Detection checks for vulnerable version of FortiOS.

QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.

Successful exploitation of the vulnerability may lead to Execute unauthorized code or commands

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Please upgrade to FortiOS version 7.4.2 or abovePlease upgrade to FortiOS version 7.2.6 or abovePlease upgrade to FortiOS version 7.0.13 or abovePlease upgrade to FortiOS version 6.4.15 or abovePlease upgrade to FortiOS version 6.2.16 or above. Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-23-328
    Vendor References

    CVEs related to QID 44176

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-328 URL Logo www.fortiguard.com/psirt/FG-IR-23-328