CVE Vulnerabilities

CVE-2023-29180

NULL Pointer Dereference

Published: Feb 22, 2024 | Modified: Dec 10, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to denial of service via specially crafted HTTP requests.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
FortiproxyFortinet1.0.0 (including)1.0.7 (including)
FortiproxyFortinet1.1.0 (including)1.1.6 (including)
FortiproxyFortinet1.2.0 (including)1.2.13 (including)
FortiproxyFortinet2.0.0 (including)2.0.13 (excluding)
FortiproxyFortinet7.0.0 (including)7.0.11 (excluding)
FortiproxyFortinet7.2.0 (including)7.2.4 (excluding)

Potential Mitigations

References