CVE-2024-46667
A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to de
Severity
Medium 6.9
CVSS 3.1
Exploited
Not listed
EPSS
0.006
47.1th percentile
Discovered by
Third party
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet
Description
A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connections.
Weakness: CWE-770
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSIEM | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSIEM
Credit
Fortinet is pleased to thank James Reno from Nuspire for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiSIEM version 7.2.0 or above Please upgrade to FortiSIEM version 7.1.6 or above