First published: Tue Jan 14 2025(Updated: )
An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS and FortiSASE FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=7.4.0<=7.4.4 | |
Fortinet FortiOS | >=7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-24-267 is significant as it can lead to a denial of service through an integer overflow vulnerability.
To fix FG-IR-24-267, update FortiOS to version 7.4.5 or higher if you are using versions between 7.4.0 and 7.4.4.
FG-IR-24-267 affects FortiOS versions 7.4.0 to 7.4.4 and all versions of FortiOS from 7.2 onwards.
FG-IR-24-267 is classified as an Integer Overflow or Wraparound vulnerability under CWE-190.
Yes, FG-IR-24-267 can be exploited by an authenticated attacker via crafted requests.