CVE-2019-15705: Input Validation
Published Nov 27, 2019
·Updated
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.
Affected Software
2 affected components
Fortinet FortiOS<=6.0.6
Fortinet FortiOS>=6.2.0<=6.2.1
Event History
Nov 27, 2019
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-15705?
CVE-2019-15705 has been classified as a Medium severity vulnerability.
2
How do I fix CVE-2019-15705?
To address CVE-2019-15705, you should upgrade FortiOS to the latest version that is not affected by this vulnerability.
3
What versions of FortiOS are affected by CVE-2019-15705?
CVE-2019-15705 affects FortiOS versions 6.0.6 and below, and 6.2.1 and below.
4
What type of attack does CVE-2019-15705 allow?
CVE-2019-15705 allows an unauthenticated remote attacker to crash the SSL VPN service.
5
What component of FortiOS is vulnerable in CVE-2019-15705?
CVE-2019-15705 involves an Improper Input Validation vulnerability in the SSL VPN portal of FortiOS.