Resource Allocation Vulnerability in Fortinet FortiSIEM Software
CVE-2024-46667

6.9MEDIUM

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
14 January 2025

Summary

A resource allocation vulnerability exists in Fortinet's FortiSIEM software across various versions, exposing the system to potential denial of service attacks. Without sufficient limits or throttling, an attacker may exploit this weakness to consume all available connections, thereby preventing legitimate TLS traffic from being processed. Organizations using affected versions of FortiSIEM should promptly review their configurations and apply necessary mitigations to safeguard their network integrity.

Affected Version(s)

FortiSIEM 7.1.0 <= 7.1.5

FortiSIEM 7.0.0 <= 7.0.3

FortiSIEM 6.7.0 <= 6.7.9

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.