Vulnerability Intelligence Report
CVE-2019-15705
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:1.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Fortinet | FortiGate | FortiOS versions 6.2.1 and below (affected), FortiOS versions 6.0.6 and below (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.262%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Fortinet, Inc. · Vendor · USA |
| Reserved | 2019-08-27T00:00:00 |
| Published | 2019-11-27T20:38:54 |
| Last Updated | 2024-10-25T14:27:42 |
Community Chatter & Buzz