A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger the sending of "blocked page" HTML data to an arbitrary victim via crafted TCP requests, potentially flooding the victim.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortios | — | Upgrade FortiOS to 7.2.1Upgrade to the latest version of FortiOSUpgrade FortiOS to 7.0.6Upgrade FortiOS to 6.4.9Upgrade FortiOS to 6.2.11 | Sep 12, 2022 | Sep 6, 2022 |
| Oracle_linux | — | Upgrade olcne-prometheus-chartUpgrade kubeletUpgrade olcneUpgrade olcne-nginxUpgrade olcne-gluster-chartUpgrade olcne-agentUpgrade olcne-extra-modulesUpgrade olcne-kubevirt-chartUpgrade olcne-metallb-chartUpgrade kubernetesUpgrade olcnectlUpgrade istioUpgrade olcne-rook-chartUpgrade olcne-multus-chartUpgrade kubectlUpgrade olcne-istio-chartUpgrade olcne-olm-chartUpgrade olcne-api-serverUpgrade istio-istioctlUpgrade olcne-utilsUpgrade olcne-calico-chartUpgrade kubeadmUpgrade olcne-oci-ccm-chartUpgrade olcne-grafana-chart | May 26, 2023 | Sep 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub