2.7
CVE-2026-84392
- EPSS 0.28%
- Veröffentlicht 08.09.2026 16:42:06
- Zuletzt bearbeitet 08.09.2026 18:35:10
- Erkennungen
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFortinet
≫
Produkt
FortiOS
Default Statusunaffected
Version <=
7.4.12
Version
7.4.0
Status
affected
Version <=
7.2.13
Version
7.2.0
Status
affected
Version <=
7.0.19
Version
7.0.0
Status
affected
Version <=
6.4.16
Version
6.4.0
Status
affected
HerstellerFortinet
≫
Produkt
FortiProxy
Default Statusunaffected
Version <=
7.6.6
Version
7.6.0
Status
affected
Version <=
7.4.14
Version
7.4.0
Status
affected
Version <=
7.2.16
Version
7.2.0
Status
affected
HerstellerFortinet
≫
Produkt
FortiPAM
Default Statusunaffected
Version
1.9.0
Status
affected
Version <=
1.8.4
Version
1.8.0
Status
affected
Version <=
1.7.2
Version
1.7.0
Status
affected
Version <=
1.6.2
Version
1.6.0
Status
affected
Version <=
1.5.1
Version
1.5.0
Status
affected
Version <=
1.4.3
Version
1.4.0
Status
affected
Version <=
1.3.1
Version
1.3.0
Status
affected
Version
1.2.0
Status
affected
Version <=
1.1.2
Version
1.1.0
Status
affected
Version <=
1.0.3
Version
1.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.204 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Fortinet | 2.7 | 1.2 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://fortiguard.fortinet.com/psirt/FG-IR-26-173