CVE-2024-26007
An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrativ
Severity
Medium 5
CVSS 3.1
Exploited
Not listed
EPSS
0.012
65.6th percentile
Discovered by
Vendor
Vendor advisory field
Published
May 14, 2024
Assigned by fortinet
Description
An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.
Weakness: CWE-703
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiOS
- fortinet · fortios
Credit
Internally discovered and reported by Theo Leleu of Fortinet Product Security team.
Vendor remediation
Please upgrade to FortiOS version 7.4.2 or above