CVE Vulnerabilities

CVE-2023-29179

NULL Pointer Dereference

Published: Feb 22, 2024 | Modified: Dec 10, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
FortiosFortinet6.4.0 (including)6.4.13 (excluding)
FortiosFortinet7.0.0 (including)7.0.12 (excluding)
FortiosFortinet7.2.0 (including)7.2.5 (excluding)

Potential Mitigations

References