First published: Tue Jan 14 2025(Updated: )
An Out-of-bounds Read vulnerability [CWE-125] in FortiOS and FortiSASE FortiOS tenant IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.
Affected Software | Affected Version | How to fix |
---|---|---|
FortiOS | =. | |
FortiOS | >=7.4.0<=7.4.4 | |
FortiOS | >=7.2.0<=7.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-24-266 is critical due to the potential for unauthorized denial of service attacks.
To fix FG-IR-24-266, upgrade FortiOS to version 7.6.1 or later; 7.4.5 or later for versions 7.4.0 to 7.4.4; or 7.2.10 or later for versions 7.2.0 to 7.2.9.
FG-IR-24-266 affects users of FortiOS and FortiSASE running specific vulnerable versions.
FG-IR-24-266 can be exploited to trigger memory consumption leading to a denial of service.
No, FG-IR-24-266 can be exploited by unauthenticated remote attackers.