Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28x5-qjqx-j9fr

Опубликовано: 09 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.4

Описание

An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.

An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.

EPSS

Процентиль: 14%
0.00047
Низкий

3.4 Low

CVSS3

Дефекты

CWE-1389
CWE-704

Связанные уязвимости

CVSS3: 3.4
nvd
больше 1 года назад

An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.

CVSS3: 3.4
fstec
больше 1 года назад

Уязвимость функции проверки IP-адресов операционных систем FortiOS и прокси-сервера для защиты от интернет-атак FortiProxy, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 14%
0.00047
Низкий

3.4 Low

CVSS3

Дефекты

CWE-1389
CWE-704