PT-2024-10211 · Fortinet · Fortios

Published

2024-09-11

·

Updated

2025-01-15

·

CVE-2024-46668

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FortiOS versions 6.4.0 through 6.4.15 FortiOS versions 7.0.0 through 7.0.15 FortiOS versions 7.2.0 through 7.2.8 FortiOS versions 7.4.0 through 7.4.4
Description The issue is related to an allocation of resources without limits or throttling, which may allow an unauthenticated remote user to consume all system memory via multiple large file uploads. This can impact the availability of protected information.
Recommendations For FortiOS versions 6.4.0 through 6.4.15, update to a version that includes a fix for this issue. For FortiOS versions 7.0.0 through 7.0.15, update to a version that includes a fix for this issue. For FortiOS versions 7.2.0 through 7.2.8, update to a version that includes a fix for this issue. For FortiOS versions 7.4.0 through 7.4.4, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to FortiOS API endpoints that may be vulnerable to large file uploads until a patch is available.

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00541
CVE-2024-46668

Affected Products

Fortios