7.5
CVSSv3

CVE-2024-46670

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: NA | VMScore: 850 | EPSS: 0.00205 | KEV: Not Included
Published: 14/01/2025 Updated: 31/01/2025

Vulnerability Summary

Out-of-bounds Read in FortiOS IPsec IKE Causes DoS

FortiOS version 7.6.0, version 7.4.4 and earlier, version 7.2.9 and earlier, and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service have an Out-of-bounds Read vulnerability [CWE-125]. This can let an unauthenticated remote attacker cause memory use issues. This might lead to Denial of Service with specially crafted requests.

Solution

Please upgrade to FortiSASE version 24.3.c or above
Please upgrade to FortiOS version 7.6.1 or above
Please upgrade to FortiOS version 7.4.5 or above
Please upgrade to FortiOS version 7.2.10 or above
Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortios 7.6.0

fortinet fortios 7.4.4

fortinet fortios 7.4.3

fortinet fortios 7.4.2

fortinet fortios 7.4.1

fortinet fortios 7.4.0

fortinet fortios 7.2.9

fortinet fortios 7.2.8

fortinet fortios 7.2.7

fortinet fortios 7.2.6

fortinet fortios 7.2.5

fortinet fortios 7.2.4

fortinet fortios 7.2.3

fortinet fortios 7.2.2

fortinet fortios 7.2.1

fortinet fortios 7.2.0

fortinet fortipam 1.4.1

fortinet fortipam 1.4.0

fortinet fortipam 1.3.0

fortinet fortipam 1.2.0

fortinet fortipam 1.1.2

fortinet fortipam 1.1.1

fortinet fortipam 1.1.0

fortinet fortipam 1.0.3

fortinet fortipam 1.0.2

fortinet fortipam 1.0.1

fortinet fortipam 1.0.0

fortinet fortios

fortinet fortiproxy

fortinet fortipam