<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>TCP Middlebox Reflection</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-073</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2022-09-06T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2022-09-06T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2022-09-06T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An improper verification of source of a communication channel vulnerability [CWE-940] in FortiOS may allow a remote and unauthenticated attacker to trigger the sending of &#34;blocked page&#34; HTML data to an arbitrary victim via crafted TCP requests, potentially flooding the victim. This is possible only if at least a firewall policy has inspection mode set to flow-based (default), AND at least a Security Profile is enabled (Web Filter, AntiVirus, IPS, DLP, Application Control, SSL, File filter).
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Denial of service
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiOS version 7.2.0FortiOS version 7.0.0 through 7.0.5FortiOS version 6.4.0 through 6.4.8FortiOS version 6.2.0 through 6.2.10FortiOS 6.0 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiOS version 6.2.11 or above,Please upgrade to FortiOS version 6.4.9 or above,Please upgrade to FortiOS version 7.0.6 or above,Please upgrade to FortiOS version 7.2.1 or above.ORFortiOS version 6.0.0 to 6.0.10 : Please upgrade IPS engine to version 4.086 or above,FortiOS version 6.2.4 to 6.2.10 : Please upgrade IPS engine to version 5.259 or above,FortiOS version 6.4.0 to 6.4.8 : Please upgrade IPS engine to version 6.122 or above,FortiOS version 7.0.0 to 7.0.5 : Please upgrade IPS engine to version 7.114 or above,FortiOS version 7.2.0 : Please upgrade IPS engine to version 7.215 or above.Workarounds:Disable or adjust security profiles that may trigger the sending of &#34;blocked page&#34; HTTP data, or use proxy-based inspection mode instead of the default flow-based inspection mode.OREmpty the replacement page in Replacement Page &gt;&gt; Extended View of Security Profiles to limit amplification factor created with block page.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:DocumentReferences>
        <cvrf:Reference>
            <cvrf:URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-073</cvrf:URL>
            <cvrf:Description>TCP Middlebox Reflection</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>[1] https://www.usenix.org/system/files/sec21fall-bock.pdf</cvrf:URL>
            <cvrf:Description>[1] https://www.usenix.org/system/files/sec21fall-bock.pdf</cvrf:Description>
        </cvrf:Reference>
    </cvrf:DocumentReferences>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiOS" Type="Product Name">
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.2.0">FortiOS 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.5">FortiOS 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.4">FortiOS 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.3">FortiOS 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.2">FortiOS 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.1">FortiOS 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-7.0.0">FortiOS 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.8">FortiOS 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.7">FortiOS 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.6">FortiOS 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.5">FortiOS 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.4">FortiOS 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.3">FortiOS 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.2">FortiOS 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.1">FortiOS 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.4.0">FortiOS 6.4.0</FullProductName>
                </Branch>
                <Branch Name="6.2.10" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.10">FortiOS 6.2.10</FullProductName>
                </Branch>
                <Branch Name="6.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.9">FortiOS 6.2.9</FullProductName>
                </Branch>
                <Branch Name="6.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.8">FortiOS 6.2.8</FullProductName>
                </Branch>
                <Branch Name="6.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.7">FortiOS 6.2.7</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.6">FortiOS 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.5">FortiOS 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.4">FortiOS 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.3">FortiOS 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.2">FortiOS 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.1">FortiOS 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.2.0">FortiOS 6.2.0</FullProductName>
                </Branch>
                <Branch Name="6.0.18" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.18">FortiOS 6.0.18</FullProductName>
                </Branch>
                <Branch Name="6.0.17" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.17">FortiOS 6.0.17</FullProductName>
                </Branch>
                <Branch Name="6.0.16" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.16">FortiOS 6.0.16</FullProductName>
                </Branch>
                <Branch Name="6.0.15" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.15">FortiOS 6.0.15</FullProductName>
                </Branch>
                <Branch Name="6.0.14" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.14">FortiOS 6.0.14</FullProductName>
                </Branch>
                <Branch Name="6.0.13" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.13">FortiOS 6.0.13</FullProductName>
                </Branch>
                <Branch Name="6.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.12">FortiOS 6.0.12</FullProductName>
                </Branch>
                <Branch Name="6.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.11">FortiOS 6.0.11</FullProductName>
                </Branch>
                <Branch Name="6.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.10">FortiOS 6.0.10</FullProductName>
                </Branch>
                <Branch Name="6.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.9">FortiOS 6.0.9</FullProductName>
                </Branch>
                <Branch Name="6.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.8">FortiOS 6.0.8</FullProductName>
                </Branch>
                <Branch Name="6.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.7">FortiOS 6.0.7</FullProductName>
                </Branch>
                <Branch Name="6.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.6">FortiOS 6.0.6</FullProductName>
                </Branch>
                <Branch Name="6.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.5">FortiOS 6.0.5</FullProductName>
                </Branch>
                <Branch Name="6.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.4">FortiOS 6.0.4</FullProductName>
                </Branch>
                <Branch Name="6.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.3">FortiOS 6.0.3</FullProductName>
                </Branch>
                <Branch Name="6.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.2">FortiOS 6.0.2</FullProductName>
                </Branch>
                <Branch Name="6.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.1">FortiOS 6.0.1</FullProductName>
                </Branch>
                <Branch Name="6.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiOS-6.0.0">FortiOS 6.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>TCP Middlebox Reflection</Title>
        <cvrf:CVE>CVE-2022-27491</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiOS-7.2.0</ProductID>
                <ProductID>FortiOS-7.0.5</ProductID>
                <ProductID>FortiOS-7.0.4</ProductID>
                <ProductID>FortiOS-7.0.3</ProductID>
                <ProductID>FortiOS-7.0.2</ProductID>
                <ProductID>FortiOS-7.0.1</ProductID>
                <ProductID>FortiOS-7.0.0</ProductID>
                <ProductID>FortiOS-6.4.8</ProductID>
                <ProductID>FortiOS-6.4.7</ProductID>
                <ProductID>FortiOS-6.4.6</ProductID>
                <ProductID>FortiOS-6.4.5</ProductID>
                <ProductID>FortiOS-6.4.4</ProductID>
                <ProductID>FortiOS-6.4.3</ProductID>
                <ProductID>FortiOS-6.4.2</ProductID>
                <ProductID>FortiOS-6.4.1</ProductID>
                <ProductID>FortiOS-6.4.0</ProductID>
                <ProductID>FortiOS-6.2.10</ProductID>
                <ProductID>FortiOS-6.2.9</ProductID>
                <ProductID>FortiOS-6.2.8</ProductID>
                <ProductID>FortiOS-6.2.7</ProductID>
                <ProductID>FortiOS-6.2.6</ProductID>
                <ProductID>FortiOS-6.2.5</ProductID>
                <ProductID>FortiOS-6.2.4</ProductID>
                <ProductID>FortiOS-6.2.3</ProductID>
                <ProductID>FortiOS-6.2.2</ProductID>
                <ProductID>FortiOS-6.2.1</ProductID>
                <ProductID>FortiOS-6.2.0</ProductID>
                <ProductID>FortiOS-6.0.18</ProductID>
                <ProductID>FortiOS-6.0.17</ProductID>
                <ProductID>FortiOS-6.0.16</ProductID>
                <ProductID>FortiOS-6.0.15</ProductID>
                <ProductID>FortiOS-6.0.14</ProductID>
                <ProductID>FortiOS-6.0.13</ProductID>
                <ProductID>FortiOS-6.0.12</ProductID>
                <ProductID>FortiOS-6.0.11</ProductID>
                <ProductID>FortiOS-6.0.10</ProductID>
                <ProductID>FortiOS-6.0.9</ProductID>
                <ProductID>FortiOS-6.0.8</ProductID>
                <ProductID>FortiOS-6.0.7</ProductID>
                <ProductID>FortiOS-6.0.6</ProductID>
                <ProductID>FortiOS-6.0.5</ProductID>
                <ProductID>FortiOS-6.0.4</ProductID>
                <ProductID>FortiOS-6.0.3</ProductID>
                <ProductID>FortiOS-6.0.2</ProductID>
                <ProductID>FortiOS-6.0.1</ProductID>
                <ProductID>FortiOS-6.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>6.6</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H/E:F/RL:U/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-073</URL>
                <Description>TCP Middlebox Reflection</Description>
            </Reference>Reference>
            <Reference>
                <URL>[1] https://www.usenix.org/system/files/sec21fall-bock.pdf</URL>
                <Description>[1] https://www.usenix.org/system/files/sec21fall-bock.pdf</Description>
            </Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>