PT-2025-2748 · Fortinet · Fortisase+1
Published
2025-01-14
·
Updated
2025-01-15
·
CVE-2024-46669
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
FortiOS versions 7.4.4 and below
FortiOS versions 7.2.10 and below
FortiSASE version 23.4.b
Description:
The issue is related to an Integer Overflow or Wraparound vulnerability. This vulnerability may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in a potential denial of service. The FortiOS tenant IPsec IKE service is affected.
Recommendations:
For FortiOS versions 7.4.4 and below, consider disabling the IPsec IKE service until a patch is available.
For FortiOS versions 7.2.10 and below, restrict access to the IPsec IKE service to minimize the risk of exploitation.
For FortiSASE version 23.4.b, avoid using crafted requests in the IPsec IKE service until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios
Fortisase