FG-IR-24-012: Real-time file system integrity checking write protection bypass
An improper access control vulnerability [CWE-284] in FortiOS may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-012?
The FG-IR-24-012 vulnerability is classified as a critical severity issue due to improper access control that could be exploited after gaining write access.
How do I fix FG-IR-24-012?
To mitigate FG-IR-24-012, update FortiOS to version 7.4.4 or later, 7.2.8 or later, or 7.0.15 or later.
Which versions of FortiOS are affected by FG-IR-24-012?
FG-IR-24-012 affects FortiOS versions 7.4.0 to 7.4.3, 7.2.5 to 7.2.7, and 7.0.12 to 7.0.14, as well as specific 6.4.x versions.
What type of vulnerability is FG-IR-24-012?
FG-IR-24-012 is an improper access control vulnerability, which falls under CWE-284.
Can FG-IR-24-012 be exploited remotely?
No, the FG-IR-24-012 vulnerability requires prior write access to the underlying system to be exploited.