CVE-2022-45861

6.5MEDIUM

An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7

发布于: 3/7/2023更新于: 11/21/2024

描述

An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2.0.11 allows a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request.

AI分析AI驱动

受影响产品

fortinetfortiproxy
fortinetfortiproxy
fortinetfortiproxy
fortinetfortiproxy
1.1.5
fortinetfortiproxy
1.1.6
fortinetfortiproxy
7.2.0
fortinetfortiproxy
7.2.1
fortinetfortios
fortinetfortios
fortinetfortios
fortinetfortios

参考资料