FG-IR-23-446: FortiOS - IP address validation mishandles zero characters
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiOS and FortiProxy IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-446?
The severity of FG-IR-23-446 is considered high due to the potential for unauthenticated attackers to bypass IP blocklists.
How do I fix FG-IR-23-446?
To fix FG-IR-23-446, upgrade FortiOS or FortiProxy to version 7.4.4 or later, or version 7.2.9 for affected versions.
Which Fortinet products are affected by FG-IR-23-446?
FG-IR-23-446 affects FortiOS versions 7.0 to 7.4.3 and FortiProxy versions up to 7.4.3.
Can FG-IR-23-446 be exploited remotely?
Yes, FG-IR-23-446 can be exploited remotely by sending crafted requests to the affected FortiOS or FortiProxy installations.
Is authentication required to exploit FG-IR-23-446?
No, exploitation of FG-IR-23-446 does not require authentication, making it particularly dangerous.