CVE-2023-33307: Fortinet FortiOS
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter.
Affected products
- Fortinet FortiOS: from 7.0.0, before 7.0.11 (fixed in 7.0.11); from 7.2.0, before 7.2.5 (fixed in 7.2.5)
- Fortinet FortiProxy: from 7.0.0, up to and including 7.0.9; from 7.2.0, up to and including 7.2.3
Published 2023-06-16. Last modified 2026-06-17.