Medium severity6.5NVD Advisory· Published Mar 7, 2023· Updated Jun 17, 2026
CVE-2022-45861
CVE-2022-45861
Description
An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2.0.11 allows a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
Affected products
10cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.2.0,<=1.2.13
- cpe:2.3:a:fortinet:fortiproxy:1.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:1.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
- (no CPE)range: 7.2.0 - 7.2.1, 7.0.0 - 7.0.7, <2.0.11
- (no CPE)range: 7.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-477nvdVendor Advisory
News mentions
0No linked articles in our index yet.