FG-IR-24-388: Denial of Service in Security Fabric Root
Published May 13, 2025
·Updated
An integer overflow or wraparound vulnerability [CWE-190] in FortiOS Security Fabric may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.
Affected Software
3 affected componentsFixes available
Fortinet FortiOS>=7.2.0<=7.2.7
Fortinet FortiOS>=7.0.0<=7.0.14
Fortinet FortiOS>=6.4
Event History
May 13, 2025
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-388?
FG-IR-24-388 has a high severity rating due to its potential to crash the csfd daemon.
2
How do I fix FG-IR-24-388?
To fix FG-IR-24-388, upgrade FortiOS to version 7.2.8, 7.0.15, or ensure you are not on the vulnerable versions of 6.4.
3
Who is affected by FG-IR-24-388?
FG-IR-24-388 affects users of FortiOS versions between 7.2.0 to 7.2.7, and 7.0.0 to 7.0.14.
4
What type of vulnerability is FG-IR-24-388?
FG-IR-24-388 is classified as an integer overflow or wraparound vulnerability (CWE-190).
5
Can FG-IR-24-388 be exploited by authenticated users?
FG-IR-24-388 can be exploited by remote unauthenticated attackers.