Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48pm-jhrv-8jrv

Опубликовано: 08 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities in Fortinet FortiOS SSL VPN webmode version 7.4.0, version 7.2.0 through 7.2.5, version 7.0.1 through 7.0.11 and version 6.4.7 through 6.4.14 and Fortinet FortiProxy SSL VPN webmode version 7.2.0 through 7.2.6 and version 7.0.0 through 7.0.12 allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities in Fortinet FortiOS SSL VPN webmode version 7.4.0, version 7.2.0 through 7.2.5, version 7.0.1 through 7.0.11 and version 6.4.7 through 6.4.14 and Fortinet FortiProxy SSL VPN webmode version 7.2.0 through 7.2.6 and version 7.0.0 through 7.0.12 allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

EPSS

Процентиль: 68%
0.00565
Низкий

7.5 High

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 7.5
nvd
10 месяцев назад

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

CVSS3: 7.5
fstec
10 месяцев назад

Уязвимость SSL-VPN-портала операционных систем FortiOS и прокси-сервера для защиты от интернет-атак FortiProxy, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 68%
0.00565
Низкий

7.5 High

CVSS3

Дефекты

CWE-908