Fortinet FortiOS
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*
- >= 7.4.0, <= 7.4.4
- >= 7.2.0, <= 7.2.11
A vulnerability allowing integer overflow or wraparound has been identified in Fortinet FortiOS versions 7.4.0 through 7.4.4, and 7.2.0 through 7.2.10, as well as FortiSASE version 23.4.b. This vulnerability exists in the FortiOS tenant IPsec IKEv1 service, where an authenticated attacker can send crafted requests to crash the IPsec tunnel, leading to a potential denial-of-service condition.
Exploitation of this vulnerability can cause a denial-of-service condition by crashing the IPsec tunnel, disrupting VPN connectivity.
Users can upgrade Fortinet FortiOS to version 7.4.5 or 7.2.12, depending on their current version. Fortinet has also released a virtual patch for this vulnerability in the FortiSASE version 24.4.a. For Fortinet FortiOS 7.4, the recommended upgrade is to version 7.4.5 or above. For Fortinet FortiOS 7.2, users should upgrade to version 7.2.12 or above. A virtual patch named 'FG-VD-10006838.0day' is available in the Fortinet Mobile Workforce Protection database update 24.090.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.