Impact
A NULL pointer dereference flaw in Fortinet FortiWeb allows an authenticated attacker to send specially crafted HTTP requests that cause the HTTP service to crash. The attack does not grant code execution or privilege escalation; instead, it results in a denial of service where the web interface becomes unavailable until the service or appliance is restarted.
Affected Systems
Affected products include FortiWeb from version 7.0 through 8.0. The vulnerability impacts FortiWeb 8.0.0‑8.0.2, 7.6.0‑7.6.6, all 7.4 releases, all 7.2 releases, and all 7.0 releases.
Risk and Exploitability
With a CVSS score of 2.5, the flaw is considered low severity. The EPSS score of less than 1% indicates a very low probability that the vulnerability will be actively exploited in the wild, and it is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the FortiWeb appliance, after which they can send malformed HTTP requests from the network. The available remediation is an official patch; no known workarounds exist.
OpenCVE Enrichment