Skip to main content
Ok1
Explorer II
December 14, 2022
Question

FortiOS - heap-based buffer overflow in sslvpnd / plans for provide patches

  • December 14, 2022
  • 9 replies
  • 5588 views

Hi

 

I have a 200D with OS 6.0.10.
The solusions listed in the PSIRT Advisories do not include the 6.0 series.
Do you know if there are plans to provide them?

9 replies

aahmadzada
Staff
Staff
December 14, 2022

FortiOS 6.0 is out of support since September 2022, so there will be no bug fixes and patches released for that version.

 

Ahmad

New Contributor III
December 14, 2022

Hi,

 

Unfortunately, FortiGate firewall 200D only supports FortiOS 6.0 which has reached EOL, so the only workaround is to disable the SSLVPN.

 

Regards,

Priyanka

Yurisk
SuperUser
SuperUser
December 14, 2022

FortiOS 6.0.15 was released on 22 of September 2022 - does it, by any chance include the fix of this CVE ?

I have a pair of 1500D which cannot be upgraded in the immediate future, but which did upgrade to 6.0.15

Thanks

Ok1
Ok1Author
Explorer II
December 14, 2022

Thanks all.
I will change from SSLVPN to IP-sec.

Ok1
Ok1Author
Explorer II
December 14, 2022

FYI, Advisory updated.

 

https://fortiguard.fortinet.com/psirt/FG-IR-22-398

Please upgrade to upcoming FortiOS version 6.0.16 or above

ede_pfau
SuperUser
SuperUser
December 14, 2022

https://www.fortiguard.com/psirt/FG-IR-22-398 states that v6.0.16 is under way.

aahmadzada
Staff
Staff
December 15, 2022

An update:
6.0.16 with the vulnerability fix should be released by the end of this week

New Contributor III
December 18, 2022
Ok1
Ok1Author
Explorer II
December 19, 2022

It's a malicious site.

ede_pfau
SuperUser
SuperUser
December 19, 2022

Forum admin has already been alerted but thanks for the notice.