Null pointer dereference leading to sslvpn DOS

Summary

Two null pointer dereference [CWE-476] vulnerabilities in FortiOS may allow a remote attacker with low privileges to crash vpn service via a crafted http request.

Version Affected Solution
FortiOS 7.6 Not affected Not Applicable
FortiOS 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.2 or above
FortiOS 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiOS 7.0 7.0 all versions Migrate to a fixed release
FortiOS 6.4 6.4 all versions Migrate to a fixed release
FortiOS 6.2 6.2 all versions Migrate to a fixed release
FortiOS 6.0 6.0 all versions Migrate to a fixed release
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Fortinet in Q4/23 has remediated this issue in FortiSASE version 23.4 and hence the customers need not perform any action.

Acknowledgement

Fortinet is pleased to thank security researcher Qian Chen (@cq674350529) from Codesafe Team of Legendsec at QI-ANXIN Group for discovering and reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication