CVE-2023-41675
10.10.2023, 17:15
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortiproxy | 7.0.0 ≤ 𝑥 ≤ 7.0.8 |
| fortinet | fortiproxy | 7.2.0 |
| fortinet | fortiproxy | 7.2.1 |
| fortinet | fortiproxy | 7.2.2 |
| fortinet | fortios | 7.0.0 ≤ 𝑥 ≤ 7.0.10 |
| fortinet | fortios | 7.2.0 ≤ 𝑥 ≤ 7.2.4 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| fortinet | fortios | 7.2.0 ≤ 𝑥 ≤ 7.2.4 | ADP |
| fortinet | fortios | 7.0.0 ≤ 𝑥 ≤ 7.0.10 | ADP |
| fortinet | fortiproxy | 7.2.0 ≤ 𝑥 ≤ 7.2.2 | ADP |
| fortinet | fortiproxy | 7.0.0 ≤ 𝑥 ≤ 7.0.8 | ADP |
Common Weakness Enumeration