VYPR
Unrated severityNVD Advisory· Published Oct 10, 2023· Updated Sep 18, 2024

CVE-2023-41675

CVE-2023-41675

Description

A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.

Affected products

4
  • Fortinet/Fortiproxyllm-fuzzy2 versions
    >=7.0.0 <=7.0.8 or >=7.2.0 <=7.2.2+ 1 more
    • (no CPE)range: >=7.0.0 <=7.0.8 or >=7.2.0 <=7.2.2
    • (no CPE)range: 7.2.0
  • Fortinet/Fortiosllm-fuzzy2 versions
    >=7.0.0 <=7.0.10 or >=7.2.0 <=7.2.4+ 1 more
    • (no CPE)range: >=7.0.0 <=7.0.10 or >=7.2.0 <=7.2.4
    • (no CPE)range: 7.2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.