CVE-2024-46670

An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unau

Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.006
48.9th percentile
Discovered by
Third party
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet

Description

An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.

Weakness: CWE-125

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Fortinet FortiProxy SASE / SSE / Secure Web cna-assigner
Vendor-reported products (3)
  • Fortinet · FortiOS
  • Fortinet · FortiProxy
  • Fortinet · FortiPAM

Credit

Fortinet is pleased to thank n3k & Yue Liu from TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiSASE version 24.3.c or above Please upgrade to FortiOS version 7.6.1 or above Please upgrade to FortiOS version 7.4.5 or above Please upgrade to FortiOS version 7.2.10 or above

Something wrong here?