CVE-2015-1452

FortiOS 5.0 Patch 7 build 4457 - Denial of Service via CAPWAP DTLS ClientHello Flood

Title source: llm
STIX 2.1

Description

The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/125
Vendor Advisory x_refsource_confirm
http://www.fortiguard.com/advisory/FG-IR-15-002/
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61661
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72383

Scores

EPSS 0.0098
EPSS Percentile 76.9%

Details

CWE
CWE-17
Status published
Products (1)
fortinet/fortios 5.0.7
Published Feb 02, 2015
Tracked Since Feb 18, 2026