CVE-2024-52963

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via speci

Severity
Low 3.5
CVSS 3.1
Exploited
Not listed
EPSS
0.007
51.4th percentile
Discovered by
Not disclosed
Published
Jan 14, 2025
Assigned by fortinet

Description

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.

Weakness: CWE-787

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Fortinet FortiProxy SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (4)
  • Fortinet · FortiProxy
  • Fortinet · FortiOS
  • Fortinet · FortiPAM
  • Siemens · RUGGEDCOM APE1808

Vendor remediation

Please upgrade to FortiOS version 7.6.1 or above