CVE-2022-27491
06.09.2022, 18:15
A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger the sending of "blocked page" HTML data to an arbitrary victim via crafted TCP requests, potentially flooding the victim.Enginsight
Vendor | Product | Version |
---|---|---|
fortinet | fortios | 6.0.0 ≤ 𝑥 ≤ 6.0.14 |
fortinet | fortios | 6.2.0 ≤ 𝑥 < 6.2.11 |
fortinet | fortios | 6.4.0 ≤ 𝑥 < 6.4.9 |
fortinet | fortios | 7.0.0 ≤ 𝑥 < 7.0.6 |
fortinet | fortios | 7.2.0 |
𝑥
= Vulnerable software versions