A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
2022-10-18T15:15:09.620
2024-11-21T06:58:25.150
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiproxy | < 1.2.13 | Yes |
Application | fortinet | fortiproxy | < 2.0.10 | Yes |
Application | fortinet | fortiproxy | < 7.0.7 | Yes |
Application | fortinet | fortiproxy | 7.2.0 | Yes |
Operating System | fortinet | fortios | < 6.2.11 | Yes |
Operating System | fortinet | fortios | < 6.4.10 | Yes |
Operating System | fortinet | fortios | < 7.0.7 | Yes |
Operating System | fortinet | fortios | 7.2.0 | Yes |