Impact
An authenticated attacker can trigger a NULL Pointer Dereference flaw that causes the httpsd daemon to crash, leading to a denial of service on the affected device. The vulnerability is classified as CWE-476 and is limited to internal authentication, so remote unauthenticated exploitation is not covered by the description.
Affected Systems
FortiOS 7.0.x (all releases from 7.0.0 through 7.0.19), 7.2.x (including 7.2.0 and 7.2.1–7.2.13 and all intermediary sub‑versions), and 7.4.x (all releases 7.4.0 through 7.4.14) are affected, as are FortiPAM 1.0.0 through 1.9.0 and all intermediate releases, and FortiProxy 7.2.0 through 7.6.6 (including all sub‑versions).
Risk and Exploitability
The CVSS score of 2.5 indicates low overall severity, and the EPSS score is not available, which suggests limited evidence of exploitation. The vulnerability is not listed in the CISA KEV catalog, further implying a lower current threat level. The attack vector is inferred to be local authenticated, requiring valid credentials to send crafted HTTP requests that trigger the crash.
OpenCVE Enrichment