FG-IR-24-381: Buffer over-read in FGFM
Published May 13, 2025
·Updated
A buffer over-read vulnerability [CWE-126] in FortiOS may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.
Affected Software
4 affected componentsFixes available
Fortinet FortiOS>=7.4.0<=7.4.3
Fortinet FortiOS>=7.2.0<=7.2.7
Fortinet FortiOS>=7.0.0<=7.0.14
Fortinet FortiOS>=6.4
Event History
May 13, 2025
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-381?
The severity of FG-IR-24-381 is classified as critical due to the potential for remote unauthenticated attackers to crash the FGFM daemon.
2
How do I fix FG-IR-24-381?
To remediate FG-IR-24-381, upgrade FortiOS to version 7.4.4, 7.2.8, or 7.0.15, depending on your current version.
3
Which versions of FortiOS are affected by FG-IR-24-381?
FortiOS versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.7, and 7.0.0 to 7.0.14 are vulnerable to FG-IR-24-381.
4
Can FG-IR-24-381 be exploited by authenticated users?
No, FG-IR-24-381 can be exploited by remote unauthenticated attackers only.
5
What type of vulnerability is FG-IR-24-381?
FG-IR-24-381 is identified as a buffer over-read vulnerability, categorized under CWE-126.