6.5
CVSSv3

CVE-2024-46669

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: NA | VMScore: 750 | EPSS: 0.00214 | KEV: Not Included
Published: 14/01/2025 Updated: 31/01/2025

Vulnerability Summary

Integer Overflow Vulnerability Leads to Denial of Service in FortiOS

FortiSASE version 23.4.b and FortiOS version 7.4.4 and below, 7.2.10 and below have an Integer Overflow or Wraparound vulnerability [CWE-190]. An authenticated attacker can crash the IPsec tunnel using crafted requests. This could cause a denial of service in the IPsec IKE service.

Solution

Please upgrade to FortiOS version 7.6.1 or above
Please upgrade to FortiOS version 7.4.5 or above
Please upgrade to FortiSASE version 24.4.a or above
Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortios 7.4.4

fortinet fortios 7.4.3

fortinet fortios 7.4.2

fortinet fortios 7.4.1

fortinet fortios 7.4.0

fortinet fortios 7.2.10

fortinet fortios 7.2.9

fortinet fortios 7.2.8

fortinet fortios 7.2.7

fortinet fortios 7.2.6

fortinet fortios 7.2.5

fortinet fortios 7.2.4

fortinet fortios 7.2.3

fortinet fortios 7.2.2

fortinet fortios 7.2.1

fortinet fortios 7.2.0

fortinet fortios