PSIRT Advisory

Denial of Service vulnerability impacts the SSL VPN service of FortiOS.

Summary

An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.

Impact

Denial of Service

Affected Products

FortiOS versions 6.2.1 and below.

FortiOS versions 6.0.6 and below.

Solutions

Please upgrade to FortiOS version 6.2.2 and above.

Please upgrade to FortiOS version 6.0.7 and above. 

Acknowledgement

Fortinet is pleased to thank Qingtang Zheng from CodeSafe Team of Legendsec at Qi'anXin Group for bringing this issue to our attention under responsible disclosure.