An access of uninitialized pointer vulnerability [CWE-824...
Moderate severity
Unreviewed
Published
Mar 7, 2023
to the GitHub Advisory Database
•
Updated Mar 22, 2023
Description
Published by the National Vulnerability Database
Mar 7, 2023
Published to the GitHub Advisory Database
Mar 7, 2023
Last updated
Mar 22, 2023
An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2.0.11 allows a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
References