CVE-2023-33305: Medium severity Fortinet FortiProxy vulnerability
A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiWeb version 7.2.0 through 7.2.1, FortiWeb version 7.0.0 through 7.0.6, FortiWeb 6.4 all versions, FortiWeb 6.3 all versions allows attacker to perform a denial of service via specially crafted HTTP requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.0.11 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.5 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.0 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.0.10 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.4 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 7.0.7 - Upgrade
Upgrade
FortiWebto a version that resolves this vulnerability.Fixed in 7.2.2 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.0.0
Event History
Frequently Asked Questions
What is the vulnerability ID for this Fortinet vulnerability?
The vulnerability ID for this Fortinet vulnerability is CVE-2023-33305.
Which software versions are affected by this vulnerability?
Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0 and more.
What is the severity of CVE-2023-33305?
The severity of CVE-2023-33305 is medium with a CVSS score of 6.5.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The CWE ID for this vulnerability is CWE-835.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following link: [FortiGuard Advisory FG-IR-22-375](https://fortiguard.com/psirt/FG-IR-22-375).