Denial of Service in Security Fabric Root

Summary

An integer overflow or wraparound vulnerability [CWE-190] in FortiOS Security Fabric may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.

Version Affected Solution
FortiOS 7.6 Not affected Not Applicable
FortiOS 7.4 Not affected Not Applicable
FortiOS 7.2 7.2.0 through 7.2.7 Upgrade to 7.2.8 or above
FortiOS 7.0 7.0.0 through 7.0.14 Upgrade to 7.0.15 or above
FortiOS 6.4 6.4 all versions Migrate to a fixed release
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Timeline

2025-05-13: Initial publication