← back
CVE-2023-41675

CVE-2023-41675

CVSS 4.8 MEDIUMEPSS 1.0%CWE-416
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Oct 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →