First published: Tue Apr 08 2025(Updated: )
Multiple potential issues, including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] in FortiOS & FortiProxy SSLVPN webmode may allow a VPN user to corrupt memory, potentially leading to code or commands execution via specifically crafted requests.
Affected Software | Affected Version | How to fix |
---|---|---|
FortiOS | ||
Fortinet FortiProxy SSL VPN webmode |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-23-165 is critical due to the potential for memory corruption and code execution.
To fix FG-IR-23-165, update FortiOS and FortiProxy to the latest versions provided by Fortinet.
Organizations using FortiOS or FortiProxy SSLVPN in web mode are potentially affected by FG-IR-23-165.
Exploitation of FG-IR-23-165 can occur through specifically crafted requests by a VPN user.
FG-IR-23-165 includes vulnerabilities related to uninitialized resources (CWE-908) and excessive iteration (CWE-834).