An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2.0.11 allows a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortiproxy | — | Upgrade to the latest version of FortiProxyUpgrade FortiProxy to 7.0.8Upgrade FortiProxy to 7.2.2Upgrade FortiProxy to 2.0.12 | Sep 30, 2026 | Mar 7, 2023 |
| Fortios | — | Upgrade FortiOS to 6.2.14Upgrade FortiOS to 6.4.12Upgrade FortiOS to 7.2.4Upgrade FortiOS to 7.0.10 | Mar 16, 2023 | Mar 7, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub