CVE-2015-1452
FortiOS 5.0 Patch 7 build 4457 - Denial of Service via CAPWAP DTLS ClientHello Flood
Title source: llmDescription
The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.
References (5)
Core 5
Core References
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/125
Vendor Advisory x_refsource_misc
http://www.security-assessment.com/files/documents/advisory/Fortinet_FortiOS_Multiple_Vulnerabilities.pdf
Vendor Advisory x_refsource_confirm
http://www.fortiguard.com/advisory/FG-IR-15-002/
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/61661
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72383
Scores
EPSS
0.0098
EPSS Percentile
76.9%
Details
CWE
CWE-17
Status
published
Products (1)
fortinet/fortios
5.0.7
Published
Feb 02, 2015
Tracked Since
Feb 18, 2026