CVE-2023-33307NULL Pointer Dereference in Fortinet Fortios

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 75.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16

Description

A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDfortinet/fortios7.0.07.0.11+1
CVEListV5fortinet/fortios7.2.07.2.4+1
CVEListV5fortinet/fortiproxy7.2.07.2.2+1
NVDfortinet/fortiproxy7.0.07.0.9+1

🔴Vulnerability Details

2
CVEList
CVE-2023-33307: A null pointer dereference in Fortinet FortiOS before 72023-06-16
GHSA
GHSA-mr3g-v6hc-ghw4: A null pointer dereference in Fortinet FortiOS before 72023-06-16

📋Vendor Advisories

1
Fortinet
Authenticated user null pointer dereference in SSL-VPN2023-06-16
CVE-2023-33307 — NULL Pointer Dereference in Fortinet | cvebase