CVE-2024-36504

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 125

Summary

CVE-2024-36504 is an out-of-bounds read vulnerability [CWE-125] affecting FortiOS SSLVPN web portal versions 7.4.0 to 7.4.4, 7.2.0 to 7.2.8, 7.0 all versions, and 6.4 all versions. An authenticated attacker can exploit this issue to cause a denial-of-service (DoS) on the SSLVPN web portal by using a specifically crafted URL. The vulnerability does not involve data exposure, but it may prevent legitimate users from accessing the SSLVPN web portal, causing operational disruptions. Fortinet recommends upgrading to affected versions' patched releases to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share