FG-IR-25-653: Multiple Unchecked Return Value leading to Null Pointer Dereference
An Unchecked Return Value vulnerability [CWE-252] in FortiOS API may allow an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-25-653?
The FG-IR-25-653 vulnerability is classified with a medium severity level due to its potential to crash the http daemon.
How do I fix FG-IR-25-653?
To fix FG-IR-25-653, you should upgrade FortiOS to version 7.6.4 or higher, or 7.4.9 or higher.
Who is affected by the FG-IR-25-653 vulnerability?
The FG-IR-25-653 vulnerability affects authenticated users of FortiOS versions 7.6.3 and lower, 7.4.8 and lower, as well as earlier versions 7.2, 7.0, and 6.4.
What type of vulnerability is FG-IR-25-653?
FG-IR-25-653 is an Unchecked Return Value vulnerability, categorized under CWE-252.
What impact does FG-IR-25-653 have on users?
FG-IR-25-653 may allow an authenticated user to cause a Null Pointer Dereference, resulting in a denial of service by crashing the http daemon.