First published: Wed Nov 27 2019(Updated: )
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | <=6.0.6 | |
Fortinet FortiOS IPS Engine | >=6.2.0<=6.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15705 has been classified as a Medium severity vulnerability.
To address CVE-2019-15705, you should upgrade FortiOS to the latest version that is not affected by this vulnerability.
CVE-2019-15705 affects FortiOS versions 6.0.6 and below, and 6.2.1 and below.
CVE-2019-15705 allows an unauthenticated remote attacker to crash the SSL VPN service.
CVE-2019-15705 involves an Improper Input Validation vulnerability in the SSL VPN portal of FortiOS.