CVE-2024-26007

An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrativ

Severity
Medium 5
CVSS 3.1
Exploited
Not listed
EPSS
0.012
63.8th percentile
Discovered by
Not disclosed
Published
May 14, 2024
Assigned by fortinet

Description

An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.

Weakness: CWE-703

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported affected versions (2)
  • Fortinet · FortiOS
  • fortinet · fortios

Vendor remediation

Please upgrade to FortiOS version 7.4.2 or above