Denial of Service Vulnerability in Fortinet FortiOS and FortiProxy Products
CVE-2023-33305

4.9MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
13 June 2023

Summary

A vulnerability in Fortinet FortiOS and FortiProxy products allows attackers to create an infinite loop through specially crafted HTTP requests. This can lead to a denial of service, impacting the availability of the affected systems. Specifically, this issue affects various versions of FortiOS, FortiProxy, and FortiWeb, making it crucial for organizations using these products to apply mitigations promptly. For detailed information and resolution steps, refer to the FortiGuard advisory.

Affected Version(s)

FortiOS 7.2.0 <= 7.2.4

FortiOS 7.0.0 <= 7.0.10

FortiOS 6.4.0 <= 6.4.13

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.