Anyone know about the OpenSSH in fortigate or fortimanager?
Hi,
We had hired VAPT to test and below is the report from them.
Fortigate 7.0.11 & Fortimanager 7.0.10
Does anyone know about this?
How to find out the OpenSSH version (not referring to SSH protocol version 2) used in Fortigate?
Or does fortigate uses any OpenSSH?
As OpenSSH v7.9 is affected by the vulnerability, CVE-2019-6111.
If it’s affected, what is the workaround to mitigate from attacks?
Thank you
Category: A06:2021-Vulnerable and Outdated Components
Vul Findings:
Vulnerable OpenSSH Version
The installed version of OpenSSH is affected by multiple vulnerabilities
- logic error
- out-of-bouns read
- double-free memory fault
- fail open permission list
- one-byte overflow
- double free in error path
- integer overflow
- improper group inheritance
- exploitation of low-privilege code
- double-free memory corruption
- CVE-2020-14871
- integer overflow
- memory side-channel attack
- CVE-2019-6111
- zero-length files creation
