Lucene search

K
nvd[email protected]NVD:CVE-2022-45861
HistoryMar 07, 2023 - 5:15 p.m.

CVE-2022-45861

2023-03-0717:15:12
CWE-824
web.nvd.nist.gov
4
cve-2022-45861
ssl vpn portal
fortinet
fortios
fortiproxy
remote attacker

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

50.5%

An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2.0.11 allows a remote authenticated attacker to crash the sslvpn daemon via an HTTP GET request.

Affected configurations

Nvd
Node
fortinetfortiproxyRange1.2.01.2.13
OR
fortinetfortiproxyRange2.0.02.0.11
OR
fortinetfortiproxyRange7.0.07.0.7
OR
fortinetfortiproxyMatch1.1.5
OR
fortinetfortiproxyMatch1.1.6
OR
fortinetfortiproxyMatch7.2.0
OR
fortinetfortiproxyMatch7.2.1
OR
fortinetfortiosRange6.2.06.2.13
OR
fortinetfortiosRange6.4.06.4.11
OR
fortinetfortiosRange7.0.07.0.9
OR
fortinetfortiosRange7.2.07.2.3
VendorProductVersionCPE
fortinetfortiproxy*cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
fortinetfortiproxy1.1.5cpe:2.3:a:fortinet:fortiproxy:1.1.5:*:*:*:*:*:*:*
fortinetfortiproxy1.1.6cpe:2.3:a:fortinet:fortiproxy:1.1.6:*:*:*:*:*:*:*
fortinetfortiproxy7.2.0cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
fortinetfortiproxy7.2.1cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
fortinetfortios*cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

50.5%

Related for NVD:CVE-2022-45861