An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-446 | Vendor Advisory |
https://fortiguard.fortinet.com/psirt/FG-IR-23-446 | Vendor Advisory |
Configurations
History
21 Nov 2024, 09:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-446 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.4 |
09 Sep 2024, 16:12
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-704 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.7 |
References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-446 - Vendor Advisory | |
First Time |
Fortinet fortios
Fortinet Fortinet fortiproxy |
|
CPE | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
09 Jul 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-09 16:15
Updated : 2024-11-21 09:01
NVD link : CVE-2024-26015
Mitre link : CVE-2024-26015
CVE.ORG link : CVE-2024-26015
JSON object : View
Products Affected
fortinet
- fortiproxy
- fortios