QID 44060
Date Published: 2023-06-21
QID 44060: Fortinet FortiOS NULL pointer dereference Vulnerability (FG-IR-23-125)
A NULL pointer dereference vulnerability [CWE-476] in FortiOS may allow an authenticated attacker to crash the SSL-VPN daemon via specially crafted HTTP requests to the /proxy endpoint.
Affected Versions:
FortiOS version 7.2.0 through 7.2.4
FortiOS version 7.0.0 through 7.0.11
FortiOS version 6.4.0 through 6.4.12
Note: Due to banner based detection this QID is kept as practice.
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow an authenticated attacker to crash the SSL-VPN daemon via specially crafted HTTP requests to the /proxy endpoint
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-23-125
Vendor References
- FG-IR-23-125 -
www.fortiguard.com/psirt/FG-IR-23-125
CVEs related to QID 44060
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-125 |
|