CVE-2024-52963

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via speci

Severity
Low 3.5
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.008
53.8th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet

Description

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.

Weakness: CWE-787

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Check your version Firewall / NGFW cna-assigner
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Fortinet FortiProxy Check your version SASE / SSE / Secure Web cna-assigner
Vendor-reported products (4)
  • Fortinet · FortiProxy
  • Fortinet · FortiOS
  • Fortinet · FortiPAM
  • Siemens · RUGGEDCOM APE1808

Credit

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security Team.

Vendor remediation

Please upgrade to FortiOS version 7.6.1 or above

Something wrong here?