Lucene search

K
fortinetFortiGuard LabsFG-IR-20-229
HistoryFeb 03, 2021 - 12:00 a.m.

FortiProxy SSL VPN buffer overflow when parsing javascript href content

2021-02-0300:00:00
FortiGuard Labs
www.fortiguard.com
24
fortiproxy
ssl vpn
buffer overflow
web portal
heap
vulnerability
web service
remote code execution
javascript

EPSS

0.008

Percentile

81.9%

A heap buffer overflow vulnerability in the FortiProxy SSL VPN web portal may cause the SSL VPN web service termination for logged in users or potential remote code execution on FortiProxy. This happens when an authenticated user visits a specifically crafted proxied webpage and is due to a failure to handle Javascript HREF content properly.