CVE-2023-29178: Access of uninitialized pointer in administrative interface API
A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests.
Other sources
An access of uninitialized pointer vulnerability [CWE-824] in FortiOS administrative interface API may allow an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this Fortinet FortiProxy vulnerability?
The vulnerability ID of this Fortinet FortiProxy vulnerability is CVE-2023-29178.
What is the severity of CVE-2023-29178?
The severity of CVE-2023-29178 is medium with a CVSS score of 4.3.
Which software versions are affected by CVE-2023-29178?
Fortinet FortiProxy versions 7.2.0 through 7.2.3 and versions before 7.0.9, as well as FortiOS versions 7.2.0 through 7.2.4 and versions before 7.0.11 are affected by CVE-2023-29178.
What is the CWE ID of CVE-2023-29178?
The CWE ID of CVE-2023-29178 is CWE-824.
How can an attacker exploit CVE-2023-29178?
An authenticated attacker can repetitively crash the httpsd process of Fortinet FortiProxy and FortiOS by sending crafted HTTP or HTTPS requests.