A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger the sending of "blocked page" HTML data to an arbitrary victim via crafted TCP requests, potentially flooding the victim.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortios | — | Upgrade to the latest version of FortiOSUpgrade FortiOS to 7.2.1Upgrade FortiOS to 6.2.11Upgrade FortiOS to 7.0.6Upgrade FortiOS to 6.4.9 | Sep 12, 2022 | Sep 6, 2022 |
| Oracle_linux | — | Upgrade olcne-oci-ccm-chartUpgrade kubeadmUpgrade olcne-calico-chartUpgrade olcne-grafana-chartUpgrade olcne-utilsUpgrade olcne-rook-chartUpgrade kubectlUpgrade olcne-olm-chartUpgrade olcne-istio-chartUpgrade istio-istioctlUpgrade olcne-multus-chartUpgrade olcne-api-serverUpgrade olcne-extra-modulesUpgrade olcne-kubevirt-chartUpgrade olcne-agentUpgrade olcneUpgrade olcne-nginxUpgrade kubernetesUpgrade olcne-gluster-chartUpgrade kubeletUpgrade olcne-prometheus-chartUpgrade istioUpgrade olcne-metallb-chartUpgrade olcnectl | May 26, 2023 | Sep 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub