Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48pm-jhrv-8jrv

Опубликовано: 08 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities in Fortinet FortiOS SSL VPN webmode version 7.4.0, version 7.2.0 through 7.2.5, version 7.0.1 through 7.0.11 and version 6.4.7 through 6.4.14 and Fortinet FortiProxy SSL VPN webmode version 7.2.0 through 7.2.6 and version 7.0.0 through 7.0.12 allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities in Fortinet FortiOS SSL VPN webmode version 7.4.0, version 7.2.0 through 7.2.5, version 7.0.1 through 7.0.11 and version 6.4.7 through 6.4.14 and Fortinet FortiProxy SSL VPN webmode version 7.2.0 through 7.2.6 and version 7.0.0 through 7.0.12 allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

EPSS

Процентиль: 48%
0.0063
Низкий

7.5 High

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость SSL-VPN-портала операционных систем FortiOS и прокси-сервера для защиты от интернет-атак FortiProxy, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 48%
0.0063
Низкий

7.5 High

CVSS3

Дефекты

CWE-908