Improper Validation of firmware Integrity

Summary

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR may allow an authenticated attacker with at least Read/Write permission on system maintenance to install a corrupted firmware image.

Version Affected Solution
FortiNDR 7.6 Not affected Not Applicable
FortiNDR 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiNDR 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiNDR 7.1 7.1 all versions Migrate to a fixed release
FortiNDR 7.0 7.0 all versions Migrate to a fixed release
FortiNDR 1.5 Not affected Not Applicable
FortiNDR 1.4 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Dipanjan Das from FortiGuard Research team.

Timeline

2025-01-14: Initial publication