Medium severity4.3NVD Advisory· Published Jun 13, 2023· Updated Jun 17, 2026
CVE-2023-29178
CVE-2023-29178
Description
A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests.
Affected products
10cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=1.1.0,<=1.1.6
- cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.3:*:*:*:*:*:*:*
- (no CPE)range: 7.2.0 through 7.2.3 and before 7.0.9
- (no CPE)range: 7.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-095nvdVendor Advisory
News mentions
0No linked articles in our index yet.