CVE-2024-46668: Multipart Form Data Denial of Service
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.
Other sources
An allocation of resources without limits or throttling vulnerability [CWE-770] in some FortiOS API endpoints may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46668?
CVE-2024-46668 has a high severity level due to its potential to allow unauthenticated remote users to consume all system memory.
How do I fix CVE-2024-46668?
To fix CVE-2024-46668, upgrade your FortiOS to version 7.4.5, 7.2.9, or 7.0.16, or upgrade from any affected version to a patched release.
Which FortiOS versions are affected by CVE-2024-46668?
CVE-2024-46668 affects FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, and 6.4.0 through 6.4.15.
Who is the vendor for CVE-2024-46668?
The vendor for CVE-2024-46668 is Fortinet.
What type of vulnerability is CVE-2024-46668?
CVE-2024-46668 is classified as an allocation of resources without limits or throttling vulnerability.