CVE-2023-33306: Authenticated user null pointer dereference in SSL-VPN
A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter.
Other sources
A NULL pointer dereference vulnerability [CWE-476] in SSL-VPN may allow an authenticated remote attacker to trigger a crash of the SSL-VPN service via crafted requests.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiOS (SSL-VPN)to a version that resolves this vulnerability.Fixed in 6.4.13 - Upgrade
Upgrade
Fortinet FortiOS (SSL-VPN)to a version that resolves this vulnerability.Fixed in 7.0.11 - Upgrade
Upgrade
Fortinet FortiOS (SSL-VPN)to a version that resolves this vulnerability.Fixed in 7.2.5 - Upgrade
Upgrade
Fortinet FortiOS (SSL-VPN)to a version that resolves this vulnerability.Fixed in 7.4.0 - Upgrade
Upgrade
Fortinet FortiProxyto a version that resolves this vulnerability.Fixed in 7.0.10 - Upgrade
Upgrade
Fortinet FortiProxyto a version that resolves this vulnerability.Fixed in 7.0.9 - Upgrade
Upgrade
Fortinet FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.3 - Upgrade
Upgrade
Fortinet FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.4
Event History
Frequently Asked Questions
What is CVE-2023-33306?
CVE-2023-33306 is a null pointer dereference vulnerability in Fortinet FortiOS, FortiProxy, and SSL VPN service.
How does CVE-2023-33306 affect Fortinet products?
CVE-2023-33306 affects Fortinet FortiOS versions before 7.2.5, before 7.0.11, and before 6.4.13. It also affects FortiProxy versions before 7.2.4 and before 7.0.10.
What is the severity of CVE-2023-33306?
CVE-2023-33306 has a severity rating of 6.5 (Medium).
How can an attacker exploit CVE-2023-33306?
An attacker can exploit CVE-2023-33306 by sending a specifically crafted request in the bookmark parameter, resulting in a denial of SSL VPN service.
Is there a fix for CVE-2023-33306?
Yes, Fortinet has released updates to address CVE-2023-33306. It is recommended to update to FortiOS 7.2.5, 7.0.11, or 6.4.13, or FortiProxy 7.2.4 or 7.0.10 to mitigate the vulnerability.