An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-446 | Vendor Advisory |
Configurations
History
09 Sep 2024, 16:12
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-704 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.7 |
References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-446 - Vendor Advisory | |
First Time |
Fortinet fortios
Fortinet Fortinet fortiproxy |
|
CPE | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
|
Summary |
|
09 Jul 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-09 16:15
Updated : 2024-09-09 16:12
NVD link : CVE-2024-26015
Mitre link : CVE-2024-26015
CVE.ORG link : CVE-2024-26015
JSON object : View
Products Affected
fortinet
- fortios
- fortiproxy