CVE Vulnerabilities

CVE-2023-42785

NULL Pointer Dereference

Published: Jan 14, 2025 | Modified: Jan 17, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 6.0.0 (including) 7.2.6 (excluding)
Fortios Fortinet 7.4.0 (including) 7.4.2 (excluding)

Potential Mitigations

References