CVE-2023-29178: Fortinet FortiOS

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests.

Affected products

  • Fortinet FortiOS: from 6.0.0, up to and including 6.0.17; from 6.2.0, up to and including 6.2.15; from 6.4.0, up to and including 6.4.13; from 7.0.0, up to and including 7.0.11; from 7.2.0, up to and including 7.2.4
  • Fortinet FortiProxy: from 1.1.0, up to and including 1.1.6; from 1.2.0, up to and including 1.2.13; from 2.0.0, up to and including 2.0.12; from 7.0.0, up to and including 7.0.9; version 7.2.0 only; version 7.2.1 only; …

Published 2023-06-13. Last modified 2026-06-17.