A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter.
The product dereferences a pointer that it expects to be valid but is NULL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortiproxy | Fortinet | 7.0.0 (including) | 7.0.10 (excluding) |
Fortiproxy | Fortinet | 7.2.0 (including) | 7.2.4 (excluding) |
Fortios | Fortinet | 6.4.0 (including) | 6.4.13 (excluding) |
Fortios | Fortinet | 7.0.0 (including) | 7.0.11 (excluding) |
Fortios | Fortinet | 7.2.0 (including) | 7.2.5 (excluding) |