CVE Vulnerabilities

CVE-2023-33305

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 13, 2023 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A loop with unreachable exit condition (infinite loop) in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiWeb version 7.2.0 through 7.2.1, FortiWeb version 7.0.0 through 7.0.6, FortiWeb 6.4 all versions, FortiWeb 6.3 all versions allows attacker to perform a denial of service via specially crafted HTTP requests.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Fortiproxy Fortinet 1.0.0 (including) 1.0.7 (including)
Fortiproxy Fortinet 1.1.0 (including) 1.1.6 (including)
Fortiproxy Fortinet 1.2.0 (including) 1.2.13 (including)
Fortiproxy Fortinet 2.0.0 (including) 2.0.12 (including)
Fortiproxy Fortinet 7.0.0 (including) 7.0.9 (including)
Fortiproxy Fortinet 7.2.0 (including) 7.2.3 (including)
Fortiweb Fortinet 6.3.0 (including) 6.3.23 (including)
Fortiweb Fortinet 6.4.0 (including) 6.4.3 (including)
Fortiweb Fortinet 7.0.0 (including) 7.0.6 (including)
Fortiweb Fortinet 7.2.0 (including) 7.2.0 (including)
Fortiweb Fortinet 7.2.1 (including) 7.2.1 (including)
Fortios Fortinet 5.0.0 (including) 5.0.14 (including)
Fortios Fortinet 5.2.0 (including) 5.2.15 (including)
Fortios Fortinet 5.4.0 (including) 5.4.13 (including)
Fortios Fortinet 5.6.0 (including) 5.6.14 (including)
Fortios Fortinet 6.0.0 (including) 6.0.17 (including)
Fortios Fortinet 6.2.0 (including) 6.2.15 (including)
Fortios Fortinet 6.4.0 (including) 6.4.13 (including)
Fortios Fortinet 7.0.0 (including) 7.0.9 (including)
Fortios Fortinet 7.2.0 (including) 7.2.4 (including)

References