CVE Vulnerabilities

CVE-2016-7541

Published: Mar 30, 2017 | Modified: Apr 04, 2017
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGates IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 5.0.0 (including) 5.0.0 (including)
Fortios Fortinet 5.0.1 (including) 5.0.1 (including)
Fortios Fortinet 5.0.2 (including) 5.0.2 (including)
Fortios Fortinet 5.0.3 (including) 5.0.3 (including)
Fortios Fortinet 5.0.4 (including) 5.0.4 (including)
Fortios Fortinet 5.0.5 (including) 5.0.5 (including)
Fortios Fortinet 5.0.6 (including) 5.0.6 (including)
Fortios Fortinet 5.0.7 (including) 5.0.7 (including)
Fortios Fortinet 5.0.8 (including) 5.0.8 (including)
Fortios Fortinet 5.0.9 (including) 5.0.9 (including)
Fortios Fortinet 5.0.10 (including) 5.0.10 (including)
Fortios Fortinet 5.0.11 (including) 5.0.11 (including)
Fortios Fortinet 5.0.12 (including) 5.0.12 (including)
Fortios Fortinet 5.0.13 (including) 5.0.13 (including)
Fortios Fortinet 5.0.14 (including) 5.0.14 (including)
Fortios Fortinet 5.2.0 (including) 5.2.0 (including)
Fortios Fortinet 5.2.1 (including) 5.2.1 (including)
Fortios Fortinet 5.2.2 (including) 5.2.2 (including)
Fortios Fortinet 5.2.3 (including) 5.2.3 (including)
Fortios Fortinet 5.2.4 (including) 5.2.4 (including)
Fortios Fortinet 5.2.5 (including) 5.2.5 (including)
Fortios Fortinet 5.2.6 (including) 5.2.6 (including)
Fortios Fortinet 5.2.7 (including) 5.2.7 (including)
Fortios Fortinet 5.2.8 (including) 5.2.8 (including)
Fortios Fortinet 5.2.9 (including) 5.2.9 (including)
Fortios Fortinet 5.2.10 (including) 5.2.10 (including)

References