FG-IR-22-477: Access of NULL pointer in SSLVPNd
An access of uninitialized pointer vulnerability [CWE-824] in the SSL-VPN portal of FortiOS & FortiProxy may allow a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-22-477?
The severity of FG-IR-22-477 is categorized as high due to the potential for a remote authenticated attacker to crash the sslvpn daemon.
How do I fix FG-IR-22-477?
To fix FG-IR-22-477, update your FortiOS or FortiProxy to the latest version provided by Fortinet that addresses this vulnerability.
What impact does FG-IR-22-477 have on my system?
FG-IR-22-477 can allow a remote authenticated attacker to crash the sslvpn daemon, resulting in denial of service.
Who is affected by FG-IR-22-477?
FG-IR-22-477 affects users of Fortinet FortiOS and FortiProxy with the vulnerable SSL-VPN portal.
Is FG-IR-22-477 being actively exploited?
As of the latest reports, there is no information confirming active exploitation of FG-IR-22-477, but it is advisable to apply patches promptly.