Lucene search

K
cveFortinetCVE-2022-45861
HistoryMar 07, 2023 - 5:15 p.m.

CVE-2022-45861

2023-03-0717:15:12
CWE-824
fortinet
web.nvd.nist.gov
36
cve-2022-45861
access of uninitialized pointer
fortinet
fortios
fortiproxy
ssl vpn
cwe-824
vulnerability
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

50.5%

An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2.0.11 allows a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request.

Affected configurations

Nvd
Node
fortinetfortiproxyRange1.2.01.2.13
OR
fortinetfortiproxyRange2.0.02.0.11
OR
fortinetfortiproxyRange7.0.07.0.7
OR
fortinetfortiproxyMatch1.1.5
OR
fortinetfortiproxyMatch1.1.6
OR
fortinetfortiproxyMatch7.2.0
OR
fortinetfortiproxyMatch7.2.1
OR
fortinetfortiosRange6.2.06.2.13
OR
fortinetfortiosRange6.4.06.4.11
OR
fortinetfortiosRange7.0.07.0.9
OR
fortinetfortiosRange7.2.07.2.3
VendorProductVersionCPE
fortinetfortiproxy*cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
fortinetfortiproxy1.1.5cpe:2.3:a:fortinet:fortiproxy:1.1.5:*:*:*:*:*:*:*
fortinetfortiproxy1.1.6cpe:2.3:a:fortinet:fortiproxy:1.1.6:*:*:*:*:*:*:*
fortinetfortiproxy7.2.0cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
fortinetfortiproxy7.2.1cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
fortinetfortios*cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Fortinet",
    "product": "FortiOS",
    "defaultStatus": "unaffected",
    "versions": [
      {
        "versionType": "semver",
        "version": "7.2.0",
        "lessThanOrEqual": "7.2.3",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "7.0.0",
        "lessThanOrEqual": "7.0.9",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "6.4.0",
        "lessThanOrEqual": "6.4.11",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "6.2.0",
        "lessThanOrEqual": "6.2.13",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Fortinet",
    "product": "FortiProxy",
    "defaultStatus": "unaffected",
    "versions": [
      {
        "versionType": "semver",
        "version": "7.2.0",
        "lessThanOrEqual": "7.2.1",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "7.0.0",
        "lessThanOrEqual": "7.0.7",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "2.0.0",
        "lessThanOrEqual": "2.0.11",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "1.2.0",
        "lessThanOrEqual": "1.2.13",
        "status": "affected"
      },
      {
        "versionType": "semver",
        "version": "1.1.5",
        "lessThanOrEqual": "1.1.6",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

50.5%

Related for CVE-2022-45861