Resource Allocation Vulnerability in Fortinet FortiSIEM Software
CVE-2024-46667
6.9MEDIUM
Summary
A resource allocation vulnerability exists in Fortinet's FortiSIEM software across various versions, exposing the system to potential denial of service attacks. Without sufficient limits or throttling, an attacker may exploit this weakness to consume all available connections, thereby preventing legitimate TLS traffic from being processed. Organizations using affected versions of FortiSIEM should promptly review their configurations and apply necessary mitigations to safeguard their network integrity.
Affected Version(s)
FortiSIEM 7.1.0 <= 7.1.5
FortiSIEM 7.0.0 <= 7.0.3
FortiSIEM 6.7.0 <= 6.7.9
References
CVSS V3.1
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published