7.5
CVSSv3

CVE-2024-46668

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: NA | VMScore: 850 | EPSS: 0.00132 | KEV: Not Included
Published: 14/01/2025 Updated: 14/01/2025

Vulnerability Summary

Unauthenticated Resource Exhaustion Vulnerability in FortiOS Allows System Memory Drain

FortiOS versions 7.4.0 to 7.4.4, 7.2.0 to 7.2.8, 7.0.0 to 7.0.15, and 6.4.0 to 6.4.15 have a vulnerability. It's an "allocation of resources without limits or throttling" issue [CWE-770]. An unauthenticated remote user can use up all system memory by uploading many large files.

Solution

Please upgrade to FortiOS version 7.6.0 or above
Please upgrade to FortiOS version 7.4.5 or above
Please upgrade to FortiOS version 7.2.9 or above
Please upgrade to FortiOS version 7.0.16 or above
Please upgrade to FortiOS version 6.4.16 or above
Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortios 7.4.4

fortinet fortios 7.4.3

fortinet fortios 7.4.2

fortinet fortios 7.4.1

fortinet fortios 7.4.0

fortinet fortios 7.2.8

fortinet fortios 7.2.7

fortinet fortios 7.2.6

fortinet fortios 7.2.5

fortinet fortios 7.2.4

fortinet fortios 7.2.3

fortinet fortios 7.2.2

fortinet fortios 7.2.1

fortinet fortios 7.2.0

fortinet fortios 7.0.15

fortinet fortios 7.0.14

fortinet fortios 7.0.13

fortinet fortios 7.0.12

fortinet fortios 7.0.11

fortinet fortios 7.0.10

fortinet fortios 7.0.9

fortinet fortios 7.0.8

fortinet fortios 7.0.7

fortinet fortios 7.0.6

fortinet fortios 7.0.5

fortinet fortios 7.0.4

fortinet fortios 7.0.3

fortinet fortios 7.0.2

fortinet fortios 7.0.1

fortinet fortios 7.0.0

fortinet fortios 6.4.15

fortinet fortios 6.4.14

fortinet fortios 6.4.13

fortinet fortios 6.4.12

fortinet fortios 6.4.11

fortinet fortios 6.4.10

fortinet fortios 6.4.9

fortinet fortios 6.4.8

fortinet fortios 6.4.7

fortinet fortios 6.4.6

fortinet fortios 6.4.5

fortinet fortios 6.4.4

fortinet fortios 6.4.3

fortinet fortios 6.4.2

fortinet fortios 6.4.1

fortinet fortios 6.4.0

fortinet fortios