PT-2023-6002 · Fortinet · Fortiproxy+1
Published
2023-10-10
·
Updated
2023-10-13
·
CVE-2023-41675
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 7.0.0 through 7.0.10
FortiOS versions 7.2.0 through 7.2.4
FortiProxy versions 7.0.0 through 7.0.8
FortiProxy versions 7.2.0 through 7.2.2
Description
A use after free vulnerability in FortiOS and FortiProxy may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection. The vulnerability is related to the use of memory after it has been freed, which can be exploited by sending specially crafted packets.
Recommendations
For FortiOS versions 7.0.0 through 7.0.10, update to a version that contains a fix for this issue.
For FortiOS versions 7.2.0 through 7.2.4, update to a version that contains a fix for this issue.
For FortiProxy versions 7.0.0 through 7.0.8, update to a version that contains a fix for this issue.
For FortiProxy versions 7.2.0 through 7.2.2, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection until a patch is available.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios
Fortiproxy