FG-IR-23-432: Firewall deny policy bypass
Published Dec 12, 2023
·Updated
An improper access control vulnerability [CWE-284] in FortiOS and FortiProxy may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP database update.
Affected Software
6 affected componentsFixes available
Fortinet FortiOS=.
Fortinet FortiOS>=7.0
Fortinet FortiOS>=6.4
Fortinet FortiProxy>=7.2.0<=7.2.3
Fortinet FortiProxy>=7.0.0<=7.0.9
Fortinet FortiProxy>=2.0.0<=2.0.12
Event History
Dec 12, 2023
Advisory Published
via FortiGuard·12:00 AM
Oct 23, 2024
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-23-432?
The FG-IR-23-432 vulnerability has a critical severity level due to its potential for unauthorized access.
2
How do I fix FG-IR-23-432?
To fix FG-IR-23-432, update FortiOS to version 7.2.1 or later, or FortiProxy to version 7.2.4 or later.
3
Who is affected by FG-IR-23-432?
FG-IR-23-432 affects FortiOS and FortiProxy versions prior to the specified remedy versions.
4
What type of vulnerability is FG-IR-23-432?
FG-IR-23-432 is an improper access control vulnerability classified under CWE-284.
5
Can FG-IR-23-432 be exploited remotely?
Yes, FG-IR-23-432 can be exploited by a remote unauthenticated attacker.