FG-IR-23-095: Access of uninitialized pointer in administrative interface API
An access of uninitialized pointer vulnerability [CWE-824] in FortiOS administrative interface API may allow an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-095?
The severity of FG-IR-23-095 is significant due to its potential to cause denial of service by crashing the httpsd process.
How do I fix FG-IR-23-095?
To mitigate FG-IR-23-095, upgrade FortiOS to version 7.2.5 or later, or 7.0.12 or later for affected versions.
Which FortiOS versions are affected by FG-IR-23-095?
FortiOS versions between 7.2.0 and 7.2.4, and versions between 7.0.0 and 7.0.11 are affected by FG-IR-23-095.
Can FG-IR-23-095 affect FortiProxy?
Yes, FG-IR-23-095 can affect FortiProxy versions between 7.2.0 and 7.2.3.
Who is affected by FG-IR-23-095?
Organizations using vulnerable versions of FortiOS and FortiProxy that allow authenticated access are affected by FG-IR-23-095.