CVE-2024-26015: FortiOS - IP address validation mishandles zero characters
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiOS and FortiProxy IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.
Other sources
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26015?
CVE-2024-26015 has a medium severity due to its potential to allow unauthorized access through IP blocklist bypass.
How do I fix CVE-2024-26015?
To remediate CVE-2024-26015, upgrade FortiOS and FortiProxy to version 7.4.4 or 7.2.9 or later.
Which Fortinet products are affected by CVE-2024-26015?
CVE-2024-26015 affects FortiOS versions from 7.0 to 7.4.3 and FortiProxy from 7.0 to 7.4.3.
Can CVE-2024-26015 be exploited remotely?
Yes, CVE-2024-26015 can be exploited remotely by an unauthenticated attacker.
What type of vulnerability is CVE-2024-26015?
CVE-2024-26015 is classified as an incorrect parsing of numbers with different radices vulnerability.