cbcvebase.
CVE-2022-29055
published 2022-10-18

CVE-2022-29055: A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.87%
54.5th percentile
A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.

Affected

11 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortios
fortinetfortios
fortinetfortios>= 6.2.0 < 6.2.116.2.11
fortinetfortios>= 6.4.0 < 6.4.106.4.10
fortinetfortios>= 7.0.0 < 7.0.77.0.7
fortinetfortiproxy
fortinetfortiproxy
fortinetfortiproxy>= 1.2.6 < 1.2.131.2.13
fortinetfortiproxy>= 2.0.0 < 2.0.102.0.10
fortinetfortiproxy>= 7.0.0 < 7.0.77.0.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.