First published: Tue May 14 2024(Updated: )
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.1 may allow an unauthenticated attacker to perform a temporary denial of service attack on the administrative interface via crafted HTTP requests.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | =. |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-24-017 is high due to its potential to allow unauthenticated attackers to disrupt service.
To fix FG-IR-24-017, upgrade FortiOS to version 7.4.2 or later.
FG-IR-24-017 affects devices running FortiOS version 7.4.1.
FG-IR-24-017 facilitates a temporary denial of service attack on the administrative interface.
Attackers can exploit FG-IR-24-017 to send crafted HTTP requests that lead to service interruption.