First published: Tue Mar 07 2023(Updated: )
An access of uninitialized pointer vulnerability [CWE-824] in the SSL-VPN portal of FortiOS & FortiProxy may allow a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | ||
Fortinet FortiProxy |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-22-477 is categorized as high due to the potential for a remote authenticated attacker to crash the sslvpn daemon.
To fix FG-IR-22-477, update your FortiOS or FortiProxy to the latest version provided by Fortinet that addresses this vulnerability.
FG-IR-22-477 can allow a remote authenticated attacker to crash the sslvpn daemon, resulting in denial of service.
FG-IR-22-477 affects users of Fortinet FortiOS and FortiProxy with the vulnerable SSL-VPN portal.
As of the latest reports, there is no information confirming active exploitation of FG-IR-22-477, but it is advisable to apply patches promptly.