CVE Vulnerabilities

CVE-2023-33305

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A loop with unreachable exit condition (infinite loop) in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiWeb version 7.2.0 through 7.2.1, FortiWeb version 7.0.0 through 7.0.6, FortiWeb 6.4 all versions, FortiWeb 6.3 all versions allows attacker to perform a denial of service via specially crafted HTTP requests.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
FortiproxyFortinet1.0.0 (including)1.0.7 (including)
FortiproxyFortinet1.1.0 (including)1.1.6 (including)
FortiproxyFortinet1.2.0 (including)1.2.13 (including)
FortiproxyFortinet2.0.0 (including)2.0.12 (including)
FortiproxyFortinet7.0.0 (including)7.0.9 (including)
FortiproxyFortinet7.2.0 (including)7.2.3 (including)
FortiwebFortinet6.3.0 (including)6.3.23 (including)
FortiwebFortinet6.4.0 (including)6.4.3 (including)
FortiwebFortinet7.0.0 (including)7.0.6 (including)
FortiwebFortinet7.2.0 (including)7.2.0 (including)
FortiwebFortinet7.2.1 (including)7.2.1 (including)
FortiosFortinet5.0.0 (including)5.0.14 (including)
FortiosFortinet5.2.0 (including)5.2.15 (including)
FortiosFortinet5.4.0 (including)5.4.13 (including)
FortiosFortinet5.6.0 (including)5.6.14 (including)
FortiosFortinet6.0.0 (including)6.0.17 (including)
FortiosFortinet6.2.0 (including)6.2.15 (including)
FortiosFortinet6.4.0 (including)6.4.13 (including)
FortiosFortinet7.0.0 (including)7.0.9 (including)
FortiosFortinet7.2.0 (including)7.2.4 (including)

References