FG-IR-22-074: Evasion by manipulating MIME attachment
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-22-074?
The severity of FG-IR-22-074 is classified as critical due to the potential for attackers to bypass the AV engine.
How do I fix FG-IR-22-074?
To fix FG-IR-22-074, ensure your FortiClient, FortiMail, and FortiOS products are updated to the latest version provided by Fortinet.
What products are affected by FG-IR-22-074?
FG-IR-22-074 affects FortiClient, FortiMail, and FortiOS AV engines.
What type of vulnerability is FG-IR-22-074?
FG-IR-22-074 is an insufficient verification of data authenticity vulnerability, specifically categorized under CWE-345.
Can FG-IR-22-074 be exploited remotely?
Yes, FG-IR-22-074 can potentially be exploited remotely by attackers manipulating MIME attachments.