FORTINET Security Advisory

Published Date: Not specified

Advisory Summary

🏷️ ⬛ UI DoS attack — FortiOS slow HTTP DoS (unauthenticated)

🔎 What happened / why it matters
FortiOS contains an “Allocation of Resources Without Limits or Throttling” weakness (CWE-770, CVSSv3 5.0) that could let an unauthenticated attacker trigger a slow HTTP Denial of Service against the FortiOS web interface using crafted HTTP requests.
This is the kind of issue that can gradually exhaust session/processing resources, potentially degrading or interrupting access for legitimate administrators and dependent services.

🛡️ Immediate actions (recommended)
1. Verify exposure: confirm whether the FortiOS web UI is reachable from untrusted networks.
2. Restrict access: limit UI access via management IP allowlists, VPN-only access, or firewall policy tightening.
3. Rate limiting / throttling: if available in your deployment path, apply WAF/reverse-proxy controls to constrain slow-HTTP behavior.
4. Patch / upgrade: upgrade FortiOS to the fixed version referenced in the PSIRT advisory.
5. Detection & response: monitor for spikes in web UI sessions, unusual request patterns, or prolonged request/connection durations.

Reference: Vendor Advisory