CVE Vulnerabilities

CVE-2023-36641

Numeric Truncation Error

Published: Nov 14, 2023 | Modified: Nov 20, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS version 7.4.0, FortiOS version 7.2.0 through 7.2.5, FortiOS version 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions allows attacker to denial of service via specifically crafted HTTP requests.

Weakness

Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

Affected Software

Name Vendor Start Version End Version
Fortiproxy Fortinet 1.0.0 (including) 1.0.7 (including)
Fortiproxy Fortinet 1.1.0 (including) 1.1.6 (including)
Fortiproxy Fortinet 1.2.0 (including) 1.2.13 (including)
Fortiproxy Fortinet 2.0.0 (including) 2.0.13 (including)
Fortiproxy Fortinet 7.0.0 (including) 7.0.10 (including)
Fortiproxy Fortinet 7.2.0 (including) 7.2.4 (including)
Fortios Fortinet 6.0.0 (including) 6.0.17 (including)
Fortios Fortinet 6.2.0 (including) 6.2.15 (including)
Fortios Fortinet 6.4.0 (including) 6.4.14 (including)
Fortios Fortinet 7.0.0 (including) 7.0.12 (including)
Fortios Fortinet 7.2.0 (including) 7.2.5 (including)

Potential Mitigations

References