First published: Tue Jun 13 2023(Updated: )
A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiWeb version 7.2.0 through 7.2.1, FortiWeb version 7.0.0 through 7.0.6, FortiWeb 6.4 all versions, FortiWeb 6.3 all versions allows attacker to perform a denial of service via specially crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiProxy | >=1.0.0<=1.0.7 | |
Fortinet FortiProxy | >=1.1.0<=1.1.6 | |
Fortinet FortiProxy | >=1.2.0<=1.2.13 | |
Fortinet FortiProxy | >=2.0.0<=2.0.12 | |
Fortinet FortiProxy | >=7.0.0<=7.0.9 | |
Fortinet FortiProxy | >=7.2.0<=7.2.3 | |
Fortinet FortiWeb | >=6.3.0<=6.3.23 | |
Fortinet FortiWeb | >=6.4.0<=6.4.3 | |
Fortinet FortiWeb | >=7.0.0<=7.0.6 | |
Fortinet FortiWeb | =7.2.0 | |
Fortinet FortiWeb | =7.2.1 | |
FortiOS | >=5.0.0<=5.0.14 | |
FortiOS | >=5.2.0<=5.2.15 | |
FortiOS | >=5.4.0<=5.4.13 | |
FortiOS | >=5.6.0<=5.6.14 | |
FortiOS | >=6.0.0<=6.0.17 | |
FortiOS | >=6.2.0<=6.2.15 | |
FortiOS | >=6.4.0<=6.4.13 | |
FortiOS | >=7.0.0<=7.0.9 | |
FortiOS | >=7.2.0<=7.2.4 |
Please upgrade to FortiPAM version 1.0.0 or above Please upgrade to FortiWeb version 7.2.2 or above Please upgrade to FortiWeb version 7.0.7 or above Please upgrade to FortiOS version 7.4.0 or above Please upgrade to FortiOS version 7.2.5 or above Please upgrade to FortiOS version 7.0.11 or above Please upgrade to FortiProxy version 7.2.4 or above Please upgrade to FortiProxy version 7.0.10 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Fortinet vulnerability is CVE-2023-33305.
Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0 and more.
The severity of CVE-2023-33305 is medium with a CVSS score of 6.5.
The CWE ID for this vulnerability is CWE-835.
You can find more information about this vulnerability at the following link: [FortiGuard Advisory FG-IR-22-375](https://fortiguard.com/psirt/FG-IR-22-375).