CVE Vulnerabilities

CVE-2023-33306

NULL Pointer Dereference

Published: Jun 16, 2023 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Fortiproxy Fortinet 7.0.0 (including) 7.0.10 (excluding)
Fortiproxy Fortinet 7.2.0 (including) 7.2.4 (excluding)
Fortios Fortinet 6.4.0 (including) 6.4.13 (excluding)
Fortios Fortinet 7.0.0 (including) 7.0.11 (excluding)
Fortios Fortinet 7.2.0 (including) 7.2.5 (excluding)

Potential Mitigations

References