CVE-2023-29179: Null Pointer Dereference
A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29179?
CVE-2023-29179 has been classified as a denial of service vulnerability, allowing attackers to disrupt service availability.
Which versions of Fortinet FortiOS are affected by CVE-2023-29179?
CVE-2023-29179 affects Fortinet FortiOS versions 7.2.0 to 7.2.4, 7.0.0 to 7.0.11, and 6.4.0 to 6.4.12.
How do I fix CVE-2023-29179?
To mitigate CVE-2023-29179, upgrade Fortinet FortiOS or FortiProxy to a version that is not affected, such as FortiOS 6.4.13 or later.
What impact does CVE-2023-29179 have if exploited?
If exploited, CVE-2023-29179 can lead to a denial of service condition, making affected services unavailable.
Is FortiProxy also affected by CVE-2023-29179?
Yes, CVE-2023-29179 affects FortiProxy versions 7.2.0 to 7.2.4 and 7.0.0 to 7.0.10.