PT-2019-14336 · Fortinet · Fortios

Published

2019-11-08

·

Updated

2019-12-16

·

CVE-2019-15705

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FortiOS versions 6.2.1 and below FortiOS versions 6.0.6 and below
Description The issue is related to an Improper Input Validation vulnerability in the SSL VPN portal of FortiOS, which may allow an unauthenticated remote attacker to crash the SSL VPN service. This can be achieved by sending a crafted POST request to the vulnerable endpoint.
Recommendations For FortiOS versions 6.2.1 and below, update to a version above 6.2.1 to resolve the issue. For FortiOS versions 6.0.6 and below, update to a version above 6.0.6 to resolve the issue. As a temporary workaround, consider restricting access to the SSL VPN portal to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15705

Affected Products

Fortios