Multiple Memory Corruption Vulnerabilities in Fortinet FortiOS and FortiProxy SSL VPN
Fortinet FortiOS and FortiProxy SSL VPN webmode are vulnerable to memory corruption issues across multiple versions. Uninitialized resources and excessive iteration flaws exist in FortiOS SSL VPN versions 7.4.0, 7.2.0 through 7.2.5, 7.0.1 through 7.0.11, and 6.4.7 through 6.4.14, as well as FortiProxy SSL VPN versions 7.2.0 through 7.2.6 and 7.0.0 through 7.0.12. These vulnerabilities can allow a VPN user to corrupt memory, potentially enabling code or command execution through specially crafted requests. The issues are related to CWE-908 (Use of Uninitialized Resource) and CWE-834 (Excessive Iteration) and could pose significant security risks for affected systems.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
fortinet fortios 7.4.0 |
||
fortinet fortios 7.2.5 |
||
fortinet fortios 7.2.4 |
||
fortinet fortios 7.2.3 |
||
fortinet fortios 7.2.2 |
||
fortinet fortios 7.2.1 |
||
fortinet fortios 7.2.0 |
||
fortinet fortios 7.0.11 |
||
fortinet fortios 7.0.10 |
||
fortinet fortios 7.0.9 |
||
fortinet fortios 7.0.8 |
||
fortinet fortios 7.0.7 |
||
fortinet fortios 7.0.6 |
||
fortinet fortios 7.0.5 |
||
fortinet fortios 7.0.4 |
||
fortinet fortios 7.0.3 |
||
fortinet fortios 7.0.2 |
||
fortinet fortios 7.0.1 |
||
fortinet fortios 6.4.14 |
||
fortinet fortios 6.4.13 |
||
fortinet fortios 6.4.12 |
||
fortinet fortios 6.4.11 |
||
fortinet fortios 6.4.10 |
||
fortinet fortios 6.4.9 |
||
fortinet fortios 6.4.8 |
||
fortinet fortios 6.4.7 |
||
fortinet fortios |
||
fortinet fortiproxy |