FG-IR-25-384: Firewall policy bypass in FSSO Terminal Services Agent
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] in FortiOS FSSO Terminal Services Agent may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-25-384?
FG-IR-25-384 is considered a critical vulnerability due to its potential for unauthorized access to protected resources.
How do I fix FG-IR-25-384?
To mitigate FG-IR-25-384, upgrade FortiOS to a version that is not affected by this vulnerability, such as 7.6.5 or later.
Who is affected by FG-IR-25-384?
FG-IR-25-384 impacts FortiOS versions from 7.0 to 7.4.9 inclusive, as well as versions 7.6.0 to 7.6.4.
What systems are vulnerable to FG-IR-25-384?
Any systems running affected versions of FortiOS, particularly those using the FSSO Terminal Services Agent, are vulnerable to FG-IR-25-384.
What does FG-IR-25-384 exploit?
FG-IR-25-384 exploits an improper verification of the source of a communication channel in FortiOS, allowing unauthorized access.