PT-2024-3557 · Fortinet · Fortios

Published

2024-05-14

·

Updated

2024-12-11

·

CVE-2024-26007

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiOS version 7.4.1
Description The issue is related to an improper check or handling of exceptional conditions, which may allow an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests. This can be achieved by sending specially formed HTTP requests.
Recommendations For Fortinet FortiOS version 7.4.1, consider temporarily restricting access to the administrative interface to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the administrative interface via crafted HTTP requests until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03862
CVE-2024-26007

Affected Products

Fortios