FG-IR-24-287: Firewall session injection in FGSP
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-287?
The severity of FG-IR-24-287 is considered critical due to the potential for unauthenticated attackers to exploit the vulnerability.
How do I fix FG-IR-24-287?
To remediate FG-IR-24-287, upgrade FortiOS to version 7.6.1 or later, or to version 7.4.6 or later if using versions 7.4.0 to 7.4.5.
What types of attacks can FG-IR-24-287 facilitate?
FG-IR-24-287 may allow attackers to inject unauthorized sessions into affected FortiOS devices.
Which versions of FortiOS are affected by FG-IR-24-287?
FG-IR-24-287 affects FortiOS versions starting from 6.4 up to 7.4.5, as well as all versions prior to 7.0 and 7.2.
Is authentication required to exploit FG-IR-24-287?
No, FG-IR-24-287 can be exploited by unauthenticated attackers, which increases the risk associated with this vulnerability.