CVE-2015-1452
high
CVSS v3
—
CVSS v2
7.8
VIR risk
7.8
Description
The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.fortiguard.com/advisory/FG-IR-15-002/
References
- http://seclists.org/fulldisclosure/2015/Jan/125
- http://secunia.com/advisories/61661
- http://www.fortiguard.com/advisory/FG-IR-15-002/
- http://www.security-assessment.com/files/documents/advisory/Fortinet_FortiOS_Multiple_Vulnerabilities.pdf
- http://www.securityfocus.com/bid/72383
- http://seclists.org/fulldisclosure/2015/Jan/125
- http://secunia.com/advisories/61661
- http://www.fortiguard.com/advisory/FG-IR-15-002/
- http://www.security-assessment.com/files/documents/advisory/Fortinet_FortiOS_Multiple_Vulnerabilities.pdf
- http://www.securityfocus.com/bid/72383
CWEs
CWE-17
Verify integrity in audit chain (admin only). AS-IS.