Integer overflow in FortiOS - CVE-2021-42755
Published: July 5, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow within the dhcpd deamon. A remote non-authenticated attacker on the local network can send specially crafted traffic to the affected system, trigger an integer overflow and perform a denial of service (DoS) attack.
Affected software
FortiProxy
FortiSwitch
FortiVoice
FortiRecorder
How to mitigate CVE-2021-42755
FortiProxy - addressed in versions 2.0.7, 7.0.1
FortiVoice - addressed in versions 6.0.11, 6.4.4
FortiRecorder - addressed in versions 6.0.11, 6.4.3
FortiSwitch - addressed in versions 6.4.10, 7.0.3