Use-after-free in FortiProxy and FortiOS - CVE-2023-41675
Published: October 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error within the Web proxy process. A remote non-authenticated attacker can send multiple specially crafted packets to the device and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that SSL deep packet inspection is enabled.
Affected software
RUGGEDCOM APE1808
FortiOS
How to mitigate CVE-2023-41675
FortiOS - addressed in versions 7.0.11, 7.2.5