FG-IR-23-328: Out-of-bounds Write in captive portal
An out-of-bounds write vulnerability [CWE-787] and a Stack-based Buffer Overflow [CWE-121] in FortiOS & FortiProxy captive portal may allow an inside attacker who has access to captive portal to execute arbitrary code or commands via specially crafted HTTP requests.
Workaround:
Set a non form-based authentication scheme:
config authentication schemeedit schemeset method methodnextend
Where <method> can be any of those :
ntlm NTLM authentication.basic Basic HTTP authentication.digest Digest HTTP authentication.negotiate Negotiate authentication.fsso Fortinet Single Sign-On (FSSO) authentication.rsso RADIUS Single Sign-On (RSSO) authentication.ssh-publickey Public key based SSH authentication.cert Client certificate authentication.saml SAML authentication
None of the enabled authentication schemes should be form-based.
Please note that only devices with captive portal enabled are affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-328?
FG-IR-23-328 has been classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix FG-IR-23-328?
To fix FG-IR-23-328, update FortiOS or FortiProxy to the latest versions as specified in the advisory.
Who is affected by FG-IR-23-328?
FortiOS and FortiProxy users with versions vulnerable to FG-IR-23-328 are at risk.
What are the implications of FG-IR-23-328 if exploited?
If exploited, FG-IR-23-328 could allow an attacker to execute arbitrary commands on the affected devices.
Is there a workaround for FG-IR-23-328?
Currently, there is no specific workaround mentioned for FG-IR-23-328; updating to a patched version is advised.