CVE-2024-46668

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0

Severity
High 7.1
CVSS 3.1
Exploited
Not listed
EPSS
0.010
58.8th percentile
Discovered by
Not disclosed
Published
Jan 14, 2025
Assigned by fortinet

Description

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.

Weakness: CWE-770

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiOS

Vendor remediation

Upgrade to FortiOS version 7.6.0 or above Upgrade to FortiOS version 7.4.5 or above Upgrade to FortiOS version 7.2.9 or above Upgrade to FortiOS version 7.0.16 or above Upgrade to FortiOS version 6.4.16 or above