Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortios | 7.4.0 | 7.4.0.x |
| fortinet / fortios | 6.4.7 | 6.4.15 |
| fortinet / fortios | 7.0.1 | 7.0.13 |
| fortinet / fortios | 7.2.0 | 7.2.6 |
| fortinet / fortiproxy | 7.0.0 | 7.0.13 |
| fortinet / fortiproxy | 7.2.0 | 7.2.7 |