Where
AND
-Infinity
0
Severity
8.1
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

HTTP/2 Rapid reset attack The HTTP/2 protocol allows clients to indicate to the server that a previous stream should be canceled by sending a RSTSTREAM frame. The protocol does not require the client and server to coordinate the cancellation in any way, the client may do it unilaterally. The client may also assume that the cancellation will take effect immediately when the server receives the RSTSTREAM frame, before any other data from that TCP connection is processed.

Abuse of this feature is called a Rapid Reset attack because it relies on the ability for an endpoint to send a RSTSTREAM frame immediately after sending a request frame, which makes the other endpoint start working and then rapidly resets the request. The request is canceled, but leaves the HTTP/2 connection open.

The HTTP/2 Rapid Reset attack built on this capability is simple: The client opens a large number of streams at once as in the standard HTTP/2 attack, but rather than waiting for a response to each request stream from the server or proxy, the client cancels each request immediately.

The ability to reset streams immediately allows each connection to have an indefinite number of requests in flight. By explicitly canceling the requests, the attacker never exceeds the limit on the number of concurrent open streams. The number of in-flight requests is no longer dependent on the round-trip time (RTT), but only on the available network bandwidth.

In a typical HTTP/2 server implementation, the server will still have to do significant amounts of work for canceled requests, such as allocating new stream data structures, parsing the query and doing header decompression, and mapping the URL to a resource. For reverse proxy implementations, the request may be proxied to the backend server before the RSTSTREAM frame is processed. The client on the other hand paid almost no costs for sending the requests. This creates an exploitable cost asymmetry between the server and the client.

Multiple software artifacts implementing HTTP/2 are affected. This advisory was originally ingested from the swift-nio-http2 repo advisory and their original conent follows.

swift-nio-http2 specific advisory swift-nio-http2 is vulnerable to a denial-of-service vulnerability in which a malicious client can create and then reset a large number of HTTP/2 streams in a short period of time. This causes swift-nio-http2 to commit to a large amount of expensive work which it then throws away, including creating entirely new Channels to serve the traffic. This can easily overwhelm an EventLoop and prevent it from making forward progress.

swift-nio-http2 1.28 contains a remediation for this issue that applies reset counter using a sliding window. This constrains the number of stream resets that may occur in a given window of time. Clients violating this limit will have their connections torn down. This allows clients to continue to cancel streams for legitimate reasons, while constraining malicious actors.

1 / 8
Source: GitHub
First published (updated )
Severity
8.8
Buffer Overflow
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests.

1 / 2
Source: MITRE
First published (updated )
Severity
7.5
AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R

An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle position to intercept and tamper with connections to the ZTNA proxy

First published (updated )
Severity
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.2, FortiSwitchManager 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.

1 / 2
Source: MITRE

Remedy

Upgrade to FortiSwitchManager version 7.2.3 or above Upgrade to FortiSwitchManager version 7.0.3 or above Fortinet remediated this issue in FortiSASE version 22.4 and hence customers do not need to perform any action. Upgrade to FortiOS version 7.4.1 or above Upgrade to FortiOS version 7.2.6 or above Upgrade to FortiPAM version 1.1.1 or above Upgrade to FortiProxy version 7.2.6 or above Upgrade to FortiProxy version 7.0.12 or above
First published (updated )
Severity
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15, FortiSwitchManager 7.2.0 through 7.2.3, FortiSwitchManager 7.0.0 through 7.0.3 allows an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is managed by a FortiManager, and if the attacker knows that FortiManager's serial number.

1 / 2
Source: MITRE

Remedy

Upgrade to FortiSwitchManager version 7.2.4 or above Upgrade to FortiSwitchManager version 7.0.4 or above Upgrade to FortiOS version 6.4.16 or above Upgrade to FortiOS version 6.2.17 or above Upgrade to FortiManager version 7.0.12 or above Upgrade to FortiManager version 6.4.15 or above Upgrade to FortiPAM version 1.3.0 or above Upgrade to FortiProxy version 7.4.3 or above Upgrade to FortiProxy version 7.2.9 or above Upgrade to FortiProxy version 7.0.16 or above
First published (updated )
Severity
7.2
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb version 7.4.0 through 7.4.5, version 7.2.0 through 7.2.10 and before 7.0.10 allows a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands.

1 / 2
Source: MITRE

Remedy

Upgrade to FortiPAM version 1.5.0 or above Upgrade to FortiPAM version 1.4.3 or above Upgrade to upcoming FortiPAM version 1.3.2 or above Upgrade to FortiProxy version 7.6.1 or above Upgrade to FortiProxy version 7.4.7 or above Upgrade to FortiProxy version 7.2.13 or above Upgrade to FortiProxy version 7.0.20 or above Upgrade to FortiOS version 7.6.0 or above Upgrade to FortiOS version 7.4.5 or above Upgrade to FortiOS version 7.2.10 or above Upgrade to FortiOS version 7.0.16 or above Upgrade to FortiOS version 6.4.16 or above Upgrade to FortiOS version 6.2.17 or above Upgrade to upcoming FortiAuthenticator version 7.0.0 or above Upgrade to FortiWeb version 7.6.1 or above Upgrade to FortiWeb version 7.4.6 or above Upgrade to FortiWeb version 7.2.11 or above Upgrade to FortiWeb version 7.0.11 or above Fortinet remediated this issue in FortiSASE version 24.4.b1 and hence customers do not need to perform any action. Upgrade to FortiSRA version 1.5.0 or above Upgrade to FortiSRA version 1.4.3 or above
First published (updated )
Severity
7.5
XSS
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:X/RC:X

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS and FortiProxy's web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via social engineering the targeted user into bookmarking a malicious samba server, then opening the bookmark.

1 / 2
Source: FortiGuard

Remedy

Please upgrade to FortiProxy version 7.4.4 or above Please upgrade to FortiProxy version 7.2.10 or above Please upgrade to FortiProxy version 7.0.17 or above Please upgrade to FortiOS version 7.4.4 or above Please upgrade to FortiOS version 7.2.8 or above Please upgrade to FortiOS version 7.0.14 or above
First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and before 6.2.13, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and before 6.2.13, Fortinet FortiVoice version 7.0.0 through 7.0.2 before 6.4.8 and Fortinet FortiWeb before 7.4.2 may allow an unauthenticated attacker in a man-in-the-middle position to impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager), via intercepting the FGFM authentication request between the management device and the managed device

1 / 2
Source: MITRE

Remedy

Please upgrade to FortiProxy version 7.4.3 or above Please upgrade to FortiProxy version 7.2.10 or above Please upgrade to FortiProxy version 7.0.16 or above Please upgrade to FortiOS version 7.6.0 or above Please upgrade to FortiOS version 7.4.5 or above Please upgrade to FortiOS version 7.2.9 or above Please upgrade to FortiOS version 7.0.16 or above Please upgrade to FortiOS version 6.2.17 or above Please upgrade to FortiVoice version 7.2.0 or above Please upgrade to FortiVoice version 7.0.3 or above Please upgrade to FortiVoice version 6.4.9 or above Please upgrade to FortiSASE version 23.1 or above Please upgrade to FortiManager version 7.4.3 or above Please upgrade to FortiManager version 7.2.5 or above Please upgrade to FortiManager version 7.0.12 or above Please upgrade to FortiManager version 6.4.15 or above Please upgrade to FortiManager version 6.2.14 or above Please upgrade to FortiWeb version 7.6.0 or above Please upgrade to FortiWeb version 7.4.3 or above Please upgrade to FortiAnalyzer version 7.4.3 or above Please upgrade to FortiAnalyzer version 7.2.5 or above Please upgrade to FortiAnalyzer version 7.0.12 or above Please upgrade to FortiAnalyzer version 6.4.15 or above Please upgrade to FortiAnalyzer version 6.2.14 or above Please upgrade to FortiGate Cloud version 24.5 or above
First published (updated )
Severity
8.8
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

1 / 2
Source: MITRE

Remedy

Please upgrade to FortiOS version 7.4.1 or above Please upgrade to FortiOS version 7.2.6 or above Please upgrade to FortiOS version 7.0.13 or above Please upgrade to FortiOS version 6.4.15 or above Please upgrade to FortiOS version 6.4.14 or above Please upgrade to FortiProxy version 7.4.0 or above Please upgrade to FortiProxy version 7.2.7 or above Please upgrade to FortiProxy version 7.0.13 or above FortiSASE is no longer impacted, issue remediated Q3/23 ## Workaround: Disable SSLVPN webmode. Alternatively, please use SSLVPN tunnel mode, IPsec (tunnel) or ZTNA (web access). https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-disable-SSL-VPN-Web-Mode-or-Tunnel-Mode-in/ta-p/217990 https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/45836/ssl-vpn-to-ipsec-vpn https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/78050/migrating-from-ssl-vpn-to-ztna
First published (updated )
Severity
7.2
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:H/RL:W/RC:C

An Improper Privilege Management vulnerability [CWE-269] affecting FortiOS, FortiProxy & FortiWeb may allow an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.

1 / 2
Source: FortiGuard

Remedy

Upgrade to upcoming FortiAuthenticator version 7.0.0 or above Upgrade to FortiOS version 7.6.2 or above Upgrade to FortiOS version 7.4.7 or above Upgrade to FortiOS version 7.2.11 or above Upgrade to FortiOS version 7.0.17 or above Upgrade to FortiOS version 6.4.16 or above Upgrade to FortiProxy version 7.6.2 or above Upgrade to FortiProxy version 7.4.8 or above Upgrade to FortiProxy version 7.2.13 or above Upgrade to FortiProxy version 7.0.20 or above Upgrade to FortiWeb version 7.6.2 or above Upgrade to FortiWeb version 7.4.7 or above
First published (updated )
Severity
7.2
Double Free
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C

A double free vulnerability [CWE-415] in FortiOS, FortiProxy & FortiPAM administrative interfaces may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.

1 / 2
Source: FortiGuard

Remedy

Upgrade to FortiProxy version 7.4.2 or above Upgrade to FortiProxy version 7.2.8 or above Upgrade to FortiProxy version 7.0.14 or above Fortinet remediated this issue in FortiSASE version 22.4 and hence customers do not need to perform any action. Upgrade to FortiOS version 7.4.1 or above Upgrade to FortiOS version 7.2.6 or above Upgrade to FortiOS version 7.0.13 or above Upgrade to FortiPAM version 1.3.0 or above Upgrade to FortiPAM version 1.2.0 or above
First published (updated )
Severity
7.2
Buffer Overflow
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H/E:P/RL:W/RC:R

A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2.1 through 7.2.5 allows attackers to escalate their privilege via specially crafted http requests.

1 / 2
Source: MITRE

Remedy

Upgrade to FortiPAM version 1.6.0 or above Upgrade to FortiPAM version 1.5.1 or above Upgrade to FortiPAM version 1.4.3 or above Fortinet remediated this issue in FortiSASE version 25.1.b and hence customers do not need to perform any action. Upgrade to FortiOS version 7.6.3 or above Upgrade to FortiOS version 7.4.7 or above Upgrade to FortiOS version 7.2.11 or above Upgrade to FortiOS version 7.0.17 or above Upgrade to FortiSRA version 1.6.0 or above Upgrade to FortiSRA version 1.5.1 or above Upgrade to FortiSRA version 1.4.3 or above Upgrade to FortiProxy version 7.6.2 or above Upgrade to FortiProxy version 7.4.8 or above Upgrade to FortiSwitchManager version 7.2.6 or above
First published (updated )
Severity
7.2
Buffer Overflow
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:R

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS, FortiManager, FortiAnalyzer, FortiManager Cloud, FortiAnalyzer Cloud, FortiProxy fgfmd daemon may allow an authenticated attacker to execute arbitrary code or commands via specifically crafted requests.

1 / 2
Source: FortiGuard

Remedy

Upgrade to FortiManager version 7.6.2 or above Upgrade to FortiManager version 7.4.6 or above Upgrade to FortiManager version 7.2.10 or above Upgrade to FortiManager version 7.0.14 or above Upgrade to FortiProxy version 7.6.2 or above Upgrade to FortiProxy version 7.4.8 or above Upgrade to FortiProxy version 7.2.13 or above Upgrade to FortiProxy version 7.0.20 or above Upgrade to FortiOS version 7.6.3 or above Upgrade to FortiOS version 7.4.7 or above Upgrade to FortiOS version 7.2.11 or above Upgrade to FortiOS version 7.0.17 or above Upgrade to FortiOS version 6.4.16 or above Upgrade to FortiManager Cloud version 7.6.3 or above Upgrade to FortiManager Cloud version 7.4.6 or above Upgrade to FortiManager Cloud version 7.2.10 or above Upgrade to FortiManager Cloud version 7.0.14 or above Upgrade to FortiAnalyzer version 7.6.3 or above Upgrade to FortiAnalyzer version 7.4.6 or above Upgrade to FortiAnalyzer version 7.2.10 or above Upgrade to FortiAnalyzer version 7.0.14 or above Upgrade to FortiAnalyzer Cloud version 7.6.2 or above Upgrade to FortiAnalyzer Cloud version 7.4.6 or above Upgrade to FortiAnalyzer Cloud version 7.2.10 or above Upgrade to FortiAnalyzer Cloud version 7.0.14 or above
First published (updated )
Severity
7.8
Buffer Overflow
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:X

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.

1 / 2
Source: MITRE

Remedy

Upgrade to FortiOS version 7.6.0 or above Upgrade to FortiOS version 7.4.2 or above Upgrade to FortiOS version 7.2.12 or above Upgrade to FortiProxy version 7.6.0 or above Upgrade to FortiProxy version 7.4.8 or above
First published (updated )
Severity
8
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS and FortiProxy GUI may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting.

1 / 2
Source: FortiGuard

Remedy

Please upgrade to FortiProxy version 7.2.5 or above Please upgrade to FortiProxy version 7.0.11 or above Please upgrade to FortiOS version 7.4.0 or above Please upgrade to FortiOS version 7.2.5 or above Please upgrade to FortiOS version 7.0.12 or above Please upgrade to FortiOS version 6.4.13 or above Please upgrade to FortiOS version 6.2.15 or above
First published (updated )
Severity
8.9
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:F/RL:X/RC:X

An improper access control vulnerability in FortiProxy SSL VPN web portal may allow an unauthenticated and remote attacker to change local SSL-VPN users' passwords via specially crafted HTTP requests.

First published (updated )
Advisory
FG-IR-20-231
Severity
8.9
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:F/RL:X/RC:X

A path traversal vulnerability in the FortiProxy SSL VPN web portal may allow a non-authenticated, remote attacker to download FortiProxy system files through specially crafted HTTP resource requests.

First published (updated )
Advisory
FG-IR-20-233

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203