FG-IR-24-058: Weak authentication in security fabric daemon
A channel accessible by non-endpoint vulnerability [CWE-300] in FortiOS & FortiProxy may allow an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-058?
The vulnerability FG-IR-24-058 is considered high severity due to the potential for unauthenticated attackers to spoof the identity of downstream devices.
How do I fix FG-IR-24-058?
To mitigate FG-IR-24-058, upgrade FortiOS to version 7.4.4 or later, or for FortiProxy, to version 7.4.4 or later, based on your current installation.
Which FortiOS versions are affected by FG-IR-24-058?
FortiOS versions 6.4.2 to 6.4.16 and 7.0.0 to 7.4.3 are affected by FG-IR-24-058.
Is FortiProxy impacted by FG-IR-24-058?
Yes, FortiProxy versions 7.0.0 to 7.0.16, 7.2.0 to 7.2.9, and 7.4.0 to 7.4.3 are also impacted by FG-IR-24-058.
What authentication requirement exists for exploiting FG-IR-24-058?
FG-IR-24-058 can be exploited by unauthenticated attackers who possess knowledge of device specific data.