CVE-2022-29055: High severity fortinet fortiproxy ssl vpn webmode vulnerability
A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-29055.
What software versions are affected by this vulnerability?
Fortinet FortiOS versions 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, and FortiProxy versions 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, and 1.2.x are affected by this vulnerability.
What is the severity of CVE-2022-29055?
The severity of CVE-2022-29055 is high with a CVSS score of 7.5.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by crashing the sslvpn daemon via an HTTP packet.
Is authentication required to exploit this vulnerability?
No, both authenticated and unauthenticated attackers can exploit this vulnerability.