Medium severity5.3NVD Advisory· Published Oct 10, 2023· Updated Jun 17, 2026
CVE-2023-41675
CVE-2023-41675
Description
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.
Affected products
9cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: >=7.0.0,<=7.0.8
- cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiproxy:7.2.2:*:*:*:*:*:*:*
- (no CPE)range: 7.2.0 - 7.2.2, 7.0.0 - 7.0.8
- (no CPE)range: 7.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-184nvdVendor Advisory
News mentions
0No linked articles in our index yet.