A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger the sending of "blocked page" HTML data to an arbitrary victim via crafted TCP requests, potentially flooding the victim.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortios | — | Upgrade FortiOS to 6.2.11Upgrade FortiOS to 6.4.9Upgrade FortiOS to 7.0.6Upgrade to the latest version of FortiOSUpgrade FortiOS to 7.2.1 | Sep 12, 2022 | Sep 6, 2022 |
| Oracle_linux | — | Upgrade olcnectlUpgrade olcne-agentUpgrade olcne-nginxUpgrade olcne-kubevirt-chartUpgrade olcne-metallb-chartUpgrade kubernetesUpgrade olcneUpgrade olcne-extra-modulesUpgrade olcne-gluster-chartUpgrade kubeletUpgrade olcne-prometheus-chartUpgrade istioUpgrade olcne-oci-ccm-chartUpgrade kubectlUpgrade olcne-utilsUpgrade olcne-grafana-chartUpgrade kubeadmUpgrade olcne-rook-chartUpgrade olcne-olm-chartUpgrade olcne-multus-chartUpgrade istio-istioctlUpgrade olcne-api-serverUpgrade olcne-istio-chartUpgrade olcne-calico-chart | May 26, 2023 | Sep 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub