FG-IR-24-219: Multipart Form Data Denial of Service
Published Jan 14, 2025
·Updated
An allocation of resources without limits or throttling vulnerability [CWE-770] in some FortiOS API endpoints may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.
Affected Software
4 affected componentsFixes available
Fortinet FortiOS>=7.4.0<=7.4.4
Fortinet FortiOS>=7.2.0<=7.2.8
Fortinet FortiOS>=7.0.0<=7.0.15
Fortinet FortiOS>=6.4.0<=6.4.15
Event History
Jan 14, 2025
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-219?
FG-IR-24-219 is classified as a significant vulnerability due to its potential for resource exhaustion.
2
How do I fix FG-IR-24-219?
To mitigate FG-IR-24-219, upgrade your FortiOS to version 7.4.5, 7.2.9, or 7.0.16 or later.
3
Who is affected by FG-IR-24-219?
FG-IR-24-219 affects users of FortiOS versions 6.4.0 to 6.4.15, 7.0.0 to 7.0.15, 7.2.0 to 7.2.8, and 7.4.0 to 7.4.4.
4
What type of attack does FG-IR-24-219 enable?
FG-IR-24-219 allows unauthenticated remote users to consume system memory through multiple large file uploads.
5
Is there a workaround for FG-IR-24-219?
There are no known workarounds for FG-IR-24-219; upgrading to a fixed version is the recommended action.