First published: Thu Feb 22 2024(Updated: )
A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to denial of service via specially crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiProxy | >=1.0.0<=1.0.7 | |
Fortinet FortiProxy | >=1.1.0<=1.1.6 | |
Fortinet FortiProxy | >=1.2.0<=1.2.13 | |
Fortinet FortiProxy | >=2.0.0<2.0.13 | |
Fortinet FortiProxy | >=7.0.0<7.0.11 | |
Fortinet FortiProxy | >=7.2.0<7.2.4 | |
Fortinet FortiOS IPS Engine | >=6.0.0<6.0.17 | |
Fortinet FortiOS IPS Engine | >=6.2.0<6.2.15 | |
Fortinet FortiOS IPS Engine | >=6.4.0<6.4.13 | |
Fortinet FortiOS IPS Engine | >=7.0.0<7.0.12 | |
Fortinet FortiOS IPS Engine | >=7.2.0<7.2.5 |
Please upgrade to FortiOS version 7.4.0 or above Please upgrade to FortiOS version 7.2.5 or above Please upgrade to FortiOS version 7.0.12 or above Please upgrade to FortiOS version 6.4.13 or above Please upgrade to FortiOS version 6.2.15 or above Please upgrade to FortiOS version 6.0.17 or above Please upgrade to FortiSASE version 22.4 or above Please upgrade to FortiProxy version 7.2.4 or above Please upgrade to FortiProxy version 7.0.11 or above Please upgrade to FortiProxy version 2.0.13 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-29180 is considered to be high, as it involves a null pointer dereference that can lead to potential denial of service.
To fix CVE-2023-29180, you should update Fortinet FortiOS or FortiProxy to the latest versions that have addressed this vulnerability.
CVE-2023-29180 affects Fortinet FortiOS versions 7.2.0 through 7.2.4 and 6.0.0 through 6.4.12, along with FortiProxy versions 7.0.0 through 7.2.3 and earlier.
CVE-2023-29180 can lead to a denial of service condition, causing affected systems to become unresponsive.
Currently, there are no documented workarounds for CVE-2023-29180, and it is strongly recommended to apply the appropriate security updates as soon as possible.