VYPR
High severity7.5NVD Advisory· Published Jan 14, 2025· Updated Jun 17, 2026

CVE-2024-46670

CVE-2024-46670

Description

An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Fortinet/Fortios3 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=7.2.0,<7.2.10
    • cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*
    • (no CPE)range: 7.6.0, 7.4.4 and below, 7.2.9 and below, 24.3.b
  • cpe:2.3:o:fortinet:fortipam:1.4.1:*:*:*:*:*:*:*
    Range: 1.4.0
  • Range: 7.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.