FG-IR-22-396: Bypass of root file system integrity checks at boot time on VM
An improper validation of integrity check value vulnerability [CWE-354] in FortiOS VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesytem integrity check in place.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-22-396?
The severity of FG-IR-22-396 is categorized as critical due to the potential for exploitation by local attackers with admin access.
How do I fix FG-IR-22-396?
To fix FG-IR-22-396, apply the latest firmware updates provided by Fortinet for FortiOS.
What systems are affected by FG-IR-22-396?
FG-IR-22-396 affects FortiOS VMs that have improper validation of integrity check values.
Who can exploit FG-IR-22-396?
A local attacker with admin privileges can exploit FG-IR-22-396 to boot a malicious image on the device.
What are the implications of FG-IR-22-396?
The implications of FG-IR-22-396 include the ability to bypass filesystem integrity checks, leading to potential unauthorized access or control of the system.