SB2020062309 - Denial of service in Fortinet FortiAnalyzer



SB2020062309 - Denial of service in Fortinet FortiAnalyzer

Published: June 23, 2020

Security Bulletin ID SB2020062309
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficient Control of Network Message Volume (CVE-ID: N/A)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an insufficient control of network message volume. A remote attacker can send specially crafted mode 6 queries to the FortiAnalyzer built-in NTP server, perform NTP amplification attacks and cause a denial of service condition on the target system. 

Note: This vulnerability affects only models that support FortiRecorder management:

  • FAZ_200F
  • FAZ_300F
  • FAZ_400E
  • FAZ_800F.
  • FAZ_1000E
  • FAZ_1000F
  • FAZ_2000E
  • FAZ_3000F
  • FAZ_3500G
  • FAZ_3700F
  • FAZ_VM64
  • FAZ_VM64_KVM


Remediation

Install update from vendor's website.