SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-41675

A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD…

MEDIUM 5.3EPSS 1.02%

Does this matter?

Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.

Description

A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
1.02% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-416
Affected
fortinet/fortiproxy · fortinet/fortios
Source
psirt@fortinet.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.