CVE-2019-17657: Slow HTTP DoS Attacks Mitigation
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.
Other sources
An Uncontrolled Resource Consumption vulnerability in multiple products may allow an attacker to cause web service portal denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly. Slow HTTP attacks are denial-of-service (DoS) attacks in which the attacker sends HTTP requests in pieces slowly, one at a time to a Web server. If an HTTP request is not complete, or if the transfer rate is very low, the server keeps its resources busy waiting for the rest of the data. When the server’s concurrent connection pool reaches its maximum, this creates a DoS. Slow HTTP attacks are easy to execute because they require only minimal resources from the attacker.
— FortiGuard
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17657?
CVE-2019-17657 is an Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6, and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3, and FortiAP-S/W2 below 6.2.2.
What is the severity of CVE-2019-17657?
The severity of CVE-2019-17657 is high with a CVSS score of 7.5.
How does CVE-2019-17657 affect Fortinet FortiSwitch?
CVE-2019-17657 may allow an attacker to cause admin webUI denial of service (DoS) by handling specially crafted HTTP requests.
Which software versions are affected by CVE-2019-17657?
Fortinet FortiSwitch versions below 3.6.11, 6.0.6, and 6.2.2, FortiAnalyzer versions below 6.2.3, FortiManager versions below 6.2.3, and FortiAP-S/W2 versions below 6.2.2 are affected by CVE-2019-17657.
How can I fix CVE-2019-17657?
To fix CVE-2019-17657, it is recommended to update Fortinet FortiSwitch to version 3.6.11, 6.0.6, or 6.2.2, FortiAnalyzer to version 6.2.3, FortiManager to version 6.2.3, and FortiAP-S/W2 to version 6.2.2 or higher.