6.5
CVSSv3

CVE-2024-36504

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: NA | VMScore: 750 | EPSS: 0.00155 | KEV: Not Included
Published: 14/01/2025 Updated: 14/01/2025

Vulnerability Summary

Denial of Service in FortiOS SSLVPN via Out-of-Bounds Read

FortiOS SSLVPN web portal versions 7.4.0 to 7.4.4, versions 7.2.0 to 7.2.8, all 7.0 versions, and all 6.4 versions have an out-of-bounds read vulnerability [CWE-125]. An authenticated attacker might cause a denial of service on the SSLVPN web portal using a specially crafted URL.

Solution

Please upgrade to FortiOS version 7.6.0 or above
Please upgrade to FortiOS version 7.4.5 or above
Please upgrade to FortiOS version 7.2.9 or above
Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortios 7.4.4

fortinet fortios 7.4.3

fortinet fortios 7.4.2

fortinet fortios 7.4.1

fortinet fortios 7.4.0

fortinet fortios 7.2.8

fortinet fortios 7.2.7

fortinet fortios 7.2.6

fortinet fortios 7.2.5

fortinet fortios 7.2.4

fortinet fortios 7.2.3

fortinet fortios 7.2.2

fortinet fortios 7.2.1

fortinet fortios 7.2.0

fortinet fortios 7.0.16

fortinet fortios 7.0.15

fortinet fortios 7.0.14

fortinet fortios 7.0.13

fortinet fortios 7.0.12

fortinet fortios 7.0.11

fortinet fortios 7.0.10

fortinet fortios 7.0.9

fortinet fortios 7.0.8

fortinet fortios 7.0.7

fortinet fortios 7.0.6

fortinet fortios 7.0.5

fortinet fortios 7.0.4

fortinet fortios 7.0.3

fortinet fortios 7.0.2

fortinet fortios 7.0.1

fortinet fortios 7.0.0

fortinet fortios 6.4.15

fortinet fortios 6.4.14

fortinet fortios 6.4.13

fortinet fortios 6.4.12

fortinet fortios 6.4.11

fortinet fortios 6.4.10

fortinet fortios 6.4.9

fortinet fortios 6.4.8

fortinet fortios 6.4.7

fortinet fortios 6.4.6

fortinet fortios 6.4.5

fortinet fortios 6.4.4

fortinet fortios 6.4.3

fortinet fortios 6.4.2

fortinet fortios 6.4.1

fortinet fortios 6.4.0

fortinet fortios