CVE-2024-52963: Out-of-bounds Write in IPSEC Daemon
A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.
Other sources
An Out-of-bounds Write in FortiOS IPSEC daemon may allow an unauthenticated attacker to perform a denial of service under certains conditions that are outside the control of the attacker.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52963?
CVE-2024-52963 is a critical vulnerability that can lead to denial of service in Fortinet FortiOS.
How do I fix CVE-2024-52963?
To remediate CVE-2024-52963, upgrade Fortinet FortiOS to version 7.6.1 or later.
Which versions of FortiOS are affected by CVE-2024-52963?
CVE-2024-52963 affects FortiOS versions 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, and 6.4.0 through 6.4.15.
Can CVE-2024-52963 be exploited remotely?
Yes, CVE-2024-52963 can be exploited remotely by sending specially crafted packets.
What types of attacks can CVE-2024-52963 facilitate?
CVE-2024-52963 may lead to denial of service attacks against vulnerable FortiOS devices.