FG-IR-24-373: Out-of-bounds Write in IPSEC Daemon
Published Jan 14, 2025
·Updated
An Out-of-bounds Write in FortiOS IPSEC daemon may allow an unauthenticated attacker to perform a denial of service under certains conditions that are outside the control of the attacker.
Affected Software
5 affected componentsFixes available
Fortinet FortiOS=.
Fortinet FortiOS>=7.4.0<=7.4.7
Fortinet FortiOS>=7.2.0<=7.2.10
Fortinet FortiOS>=7.0
Fortinet FortiOS>=6.4
Event History
Jan 14, 2025
Advisory Published
via FortiGuard·12:00 AM
Feb 18, 2025
Advisory Published
via FortiGuard·09:11 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-373?
The severity of FG-IR-24-373 is significant as it allows an unauthenticated attacker to potentially cause a denial of service.
2
How do I fix FG-IR-24-373?
To fix FG-IR-24-373, upgrade to FortiOS version 7.6.1 or above, or version 7.4.8 or above, or 7.2.11 or above, depending on your current version.
3
Which FortiOS versions are affected by FG-IR-24-373?
FortiOS versions 7.0, 6.4, and versions 7.2.0 to 7.2.10, 7.4.0 to 7.4.7 are affected by FG-IR-24-373.
4
Can FG-IR-24-373 be exploited remotely?
Yes, FG-IR-24-373 can be exploited remotely by unauthenticated attackers under specific conditions.
5
What type of vulnerability is FG-IR-24-373?
FG-IR-24-373 is classified as an Out-of-bounds Write vulnerability.