FG-IR-24-250: Unchecked boundary length causing multiple logic flaws
An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS may allow a remote unauthenticated attacker to prevent access to the GUI via specially crafted requests directed at specific endpoints.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-250?
The FG-IR-24-250 vulnerability is considered a critical issue due to its potential to allow remote unauthenticated attacks.
How do I fix FG-IR-24-250?
To remediate FG-IR-24-250, update FortiOS to version 7.6.1 or later, or apply the appropriate patches for earlier affected versions.
What is the impact of FG-IR-24-250?
An attacker exploiting FG-IR-24-250 can prevent access to the FortiOS GUI by sending specially crafted requests.
Who is affected by FG-IR-24-250?
FG-IR-24-250 affects various versions of FortiOS, specifically those prior to the fixed versions mentioned in the advisory.
Can FG-IR-24-250 be exploited remotely?
Yes, FG-IR-24-250 can be exploited remotely by an unauthenticated attacker, highlighting its critical nature.