PT-2020-6793 · Fortinet · Fortigate+1

Published

2020-09-24

·

Updated

2025-01-21

·

CVE-2020-12819

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier
Description A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet, when tunnel mode is enabled. Arbitrary code execution may be theoretically possible, albeit practically very difficult to achieve in this context.
Recommendations For FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier, consider disabling the tunnel mode or restricting access to the SSL VPN daemon until a patch is available. As a temporary workaround, avoid using large LCP packets in the affected API endpoint. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2022-06515
CVE-2020-12819

Affected Products

Fortigate
Fortios