A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger the sending of "blocked page" HTML data to an arbitrary victim via crafted TCP requests, potentially flooding the victim.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortios | — | Upgrade FortiOS to 7.2.1Upgrade to the latest version of FortiOSUpgrade FortiOS to 6.4.9Upgrade FortiOS to 7.0.6Upgrade FortiOS to 6.2.11 | Sep 12, 2022 | Sep 6, 2022 |
| Oracle_linux | — | Upgrade olcne-utilsUpgrade olcne-istio-chartUpgrade olcne-oci-ccm-chartUpgrade kubectlUpgrade olcne-rook-chartUpgrade olcne-api-serverUpgrade olcne-grafana-chartUpgrade olcne-calico-chartUpgrade istio-istioctlUpgrade kubeadmUpgrade olcne-multus-chartUpgrade olcne-olm-chartUpgrade olcne-kubevirt-chartUpgrade olcne-extra-modulesUpgrade kubernetesUpgrade istioUpgrade olcne-metallb-chartUpgrade olcneUpgrade olcne-gluster-chartUpgrade olcnectlUpgrade olcne-nginxUpgrade olcne-agentUpgrade olcne-prometheus-chartUpgrade kubelet | May 26, 2023 | Sep 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub