FG-IR-24-266: Out of bounds read in ipsec ike
Published Jan 14, 2025
·Updated
An Out-of-bounds Read vulnerability [CWE-125] in FortiOS and FortiSASE FortiOS tenant IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.
Affected Software
3 affected componentsFixes available
Fortinet FortiOS=.
Fortinet FortiOS>=7.4.0<=7.4.4
Fortinet FortiOS>=7.2.0<=7.2.9
Event History
Jan 14, 2025
Advisory Published
via FortiGuard·12:00 AM
Jan 15, 2025
Advisory Published
via FortiGuard·10:47 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-266?
The severity of FG-IR-24-266 is critical due to the potential for unauthorized denial of service attacks.
2
How do I fix FG-IR-24-266?
To fix FG-IR-24-266, upgrade FortiOS to version 7.6.1 or later; 7.4.5 or later for versions 7.4.0 to 7.4.4; or 7.2.10 or later for versions 7.2.0 to 7.2.9.
3
Who is affected by FG-IR-24-266?
FG-IR-24-266 affects users of FortiOS and FortiSASE running specific vulnerable versions.
4
What type of attack can FG-IR-24-266 be exploited for?
FG-IR-24-266 can be exploited to trigger memory consumption leading to a denial of service.
5
Is authentication required to exploit FG-IR-24-266?
No, FG-IR-24-266 can be exploited by unauthenticated remote attackers.