CVE Vulnerabilities

CVE-2023-29179

NULL Pointer Dereference

Published: Feb 22, 2024 | Modified: Dec 10, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 6.4.0 (including) 6.4.13 (excluding)
Fortios Fortinet 7.0.0 (including) 7.0.12 (excluding)
Fortios Fortinet 7.2.0 (including) 7.2.5 (excluding)

Potential Mitigations

References