Insufficient Control of Network Message Volume in FortiAnalyzer - #VU29202
Published: June 23, 2020
FortiAnalyzer
Fortinet, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an insufficient control of network message volume. A remote attacker can send specially crafted mode 6 queries to the FortiAnalyzer built-in NTP server, perform NTP amplification attacks and cause a denial of service condition on the target system.
Note: This vulnerability affects only models that support FortiRecorder management:
- FAZ_200F
- FAZ_300F
- FAZ_400E
- FAZ_800F.
- FAZ_1000E
- FAZ_1000F
- FAZ_2000E
- FAZ_3000F
- FAZ_3500G
- FAZ_3700F
- FAZ_VM64
- FAZ_VM64_KVM