VYPR
Medium severity5.3NVD Advisory· Published Oct 10, 2023· Updated Jun 17, 2026

CVE-2023-41675

CVE-2023-41675

Description

A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.

Affected products

9
  • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=7.0.0,<=7.0.8
    • cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiproxy:7.2.2:*:*:*:*:*:*:*
    • (no CPE)range: 7.2.0 - 7.2.2, 7.0.0 - 7.0.8
    • (no CPE)range: 7.2.0
  • Fortinet/Fortios3 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=7.0.0,<=7.0.10
    • (no CPE)range: 7.2.0 - 7.2.4, 7.0.0 - 7.0.10
    • (no CPE)range: 7.2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.