CVE-2023-29179NULL Pointer Dereference in Fortinet Fortios

Severity
6.5MEDIUMNVD
EPSS
0.7%
top 28.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22

Description

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDfortinet/fortios6.4.06.4.13+2
NVDfortinet/fortiproxy7.0.07.0.11+1
CVEListV5fortinet/fortios7.2.07.2.4+2
CVEListV5fortinet/fortiproxy7.2.07.2.4+1

🔴Vulnerability Details

2
CVEList
CVE-2023-29179: A null pointer dereference in Fortinet FortiOS version 72024-02-22
GHSA
GHSA-jvwr-fmgq-5q3g: A null pointer dereference in Fortinet FortiOS version 72024-02-22

📋Vendor Advisories

1
Fortinet
Null pointer dereference in sslvpnd proxy endpoint2024-02-22
CVE-2023-29179 — NULL Pointer Dereference in Fortinet | cvebase