Fortinet Update
2968Warning Date
Severity Level
Warning Number
Target Sector
23 June, 2020
● High
2020-1380
All
Description:
Fortinet has released security update to address a vulnerability in the following product:
- FortiAnalyzer
- 6.4.0, 6.2.3 and below
Only models that support FortiRecorder management are impacted:
- FAZ_200F
- FAZ_300F
- FAZ_400E
- FAZ_800F.
- FAZ_1000E
- FAZ_1000F
- FAZ_2000E
- FAZ_3000F
- FAZ_3500G
- FAZ_3700F
- FAZ_VM64
- FAZ_VM64_KVM
Threats:
Remote attacker could exploit this vulnerability by conducting NTP amplification attack, thereby causing reflected denial of service (DoS).
Best practice and Recommendations:
The CERT team encourages users to review Fortinet security advisory and apply the necessary update: