CVE-2024-26007: Node.js crash over administrative interface
An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.
Other sources
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.1 may allow an unauthenticated attacker to perform a temporary denial of service attack on the administrative interface via crafted HTTP requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26007?
The severity of CVE-2024-26007 is determined to be significant due to its potential for denial of service attacks on the FortiOS administrative interface.
How do I fix CVE-2024-26007?
To fix CVE-2024-26007, upgrade Fortinet FortiOS to version 7.4.2 or later.
Which versions of FortiOS are affected by CVE-2024-26007?
CVE-2024-26007 affects Fortinet FortiOS version 7.4.1.
Who can exploit CVE-2024-26007?
Any unauthenticated attacker can exploit CVE-2024-26007 by sending crafted HTTP requests.
What kind of vulnerability is CVE-2024-26007 classified as?
CVE-2024-26007 is classified as an improper check or handling of exceptional conditions vulnerability.