Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-33305


A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiWeb version 7.2.0 through 7.2.1, FortiWeb version 7.0.0 through 7.0.6, FortiWeb 6.4 all versions, FortiWeb 6.3 all versions allows attacker to perform a denial of service via specially crafted HTTP requests.


Published

2023-06-13T09:15:18.563

Last Modified

2024-11-21T08:05:22.690

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-835
  • Type: Primary
    CWE-835

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiproxy ≤ 1.0.7 Yes
Application fortinet fortiproxy ≤ 1.1.6 Yes
Application fortinet fortiproxy ≤ 1.2.13 Yes
Application fortinet fortiproxy ≤ 2.0.12 Yes
Application fortinet fortiproxy ≤ 7.0.9 Yes
Application fortinet fortiproxy ≤ 7.2.3 Yes
Application fortinet fortiweb ≤ 6.3.23 Yes
Application fortinet fortiweb ≤ 6.4.3 Yes
Application fortinet fortiweb ≤ 7.0.6 Yes
Application fortinet fortiweb 7.2.0 Yes
Application fortinet fortiweb 7.2.1 Yes
Operating System fortinet fortios ≤ 5.0.14 Yes
Operating System fortinet fortios ≤ 5.2.15 Yes
Operating System fortinet fortios ≤ 5.4.13 Yes
Operating System fortinet fortios ≤ 5.6.14 Yes
Operating System fortinet fortios ≤ 6.0.17 Yes
Operating System fortinet fortios ≤ 6.2.15 Yes
Operating System fortinet fortios ≤ 6.4.13 Yes
Operating System fortinet fortios ≤ 7.0.9 Yes
Operating System fortinet fortios ≤ 7.2.4 Yes

References