Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-29055


A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.


Published

2022-10-18T15:15:09.620

Last Modified

2024-11-21T06:58:25.150

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-824

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiproxy < 1.2.13 Yes
Application fortinet fortiproxy < 2.0.10 Yes
Application fortinet fortiproxy < 7.0.7 Yes
Application fortinet fortiproxy 7.2.0 Yes
Operating System fortinet fortios < 6.2.11 Yes
Operating System fortinet fortios < 6.4.10 Yes
Operating System fortinet fortios < 7.0.7 Yes
Operating System fortinet fortios 7.2.0 Yes

References