Executive brief
A heap buffer overflow vulnerability in the SSL VPN web portal of Fortinet FortiOS and FortiProxy occurs when proxying webpages due to improper handling of JavaScript href data. This flaw can allow a remote attacker to cause the termination of the SSL VPN web service for logged-in users.
Affected products
- Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier
- Fortinet FortiProxy 2.0.0, 1.2.8 and earlier
Timeline
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-10: disclosed
- 2022-01-10: exploited: Reported as exploited in the wild per CISA KEV and advisory metadata.