FortiOS Double Free Vulnerability

MEDIUM (6.6) No Patch (584 days)

Threat Intelligence

Low Risk
EPSS Score: 0.23% chance of exploitation (percentile: 46%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

Fortinet FortiOS is a network security platform used by organizations to manage and secure their networks. The double free vulnerability in FortiOS 6.4 all versions allows a privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests, potentially leading to arbitrary code execution.

Am I affected?

You're affected if you use Fortinet FortiOS version 6.4. Check with: grep 'FortiOS 6.4' /var/log/syslog (Note: This command is specific to Linux and may not work on other operating systems.)

This is Fortinet FortiOS, NOT Cisco ASA or Juniper SRX.

Affected Products

Fortinet / FortiOS

How to fix

Upgrade to FortiOS 7.4 using the official upgrade tool at: https://docs.fortinet.com/upgrade-tool
- If immediate mitigation isn't possible:
- Restrict network access to your FortiOS instance (firewall it from the public internet)
- Monitor for suspicious HTTP or HTTPS requests