FG-IR-24-267: Integer Overflow in ipsec ike
An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS and FortiSASE FortiOS tenant IPsec IKEv1 service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-267?
The severity of FG-IR-24-267 is significant as it can lead to a denial of service through an integer overflow vulnerability.
How do I fix FG-IR-24-267?
To fix FG-IR-24-267, update FortiOS to version 7.4.5 or higher if you are using versions between 7.4.0 and 7.4.4.
Who is affected by FG-IR-24-267?
FG-IR-24-267 affects FortiOS versions 7.4.0 to 7.4.4 and all versions of FortiOS from 7.2 onwards.
What type of vulnerability is FG-IR-24-267?
FG-IR-24-267 is classified as an Integer Overflow or Wraparound vulnerability under CWE-190.
Can FG-IR-24-267 be exploited remotely?
Yes, FG-IR-24-267 can be exploited by an authenticated attacker via crafted requests.