CVE-2024-26008: FGFM protocol allows unauthenticated reset of the connection
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests.
Other sources
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS, FortiProxy, FortiPAM & FortiSwitchManager fgfm daemon may allow an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What vulnerabilities are associated with CVE-2024-26008?
CVE-2024-26008 involves an improper check or handling of exceptional conditions in FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager versions specified.
What versions are affected by CVE-2024-26008?
CVE-2024-26008 affects FortiOS versions 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy versions 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0, and FortiSwitchManager versions 7.2.0 through 7.2.3 and 7.0.0.
How do I fix CVE-2024-26008?
To fix CVE-2024-26008, upgrade FortiOS to version 7.4.4 or 7.2.8, FortiProxy to version 7.4.4 or 7.2.10, and FortiSwitchManager to version 7.2.4 or 7.0.4.
What is the impact of CVE-2024-26008?
The impact of CVE-2024-26008 can potentially lead to unauthorized access or system instability due to improper handling of exceptional conditions.
Is FortiPAM vulnerable in CVE-2024-26008?
Yes, FortiPAM is also affected by CVE-2024-26008 if it is running a version prior to 1.2.0.