CVE-2024-46668: Fortinet FortiOS
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.
Affected products
- Fortinet FortiOS: from 6.4.0, before 6.4.16 (fixed in 6.4.16); from 7.0.0, before 7.0.16 (fixed in 7.0.16); from 7.2.0, before 7.2.9 (fixed in 7.2.9); from 7.4.0, before 7.4.5 (fixed in 7.4.5)
Published 2025-01-14. Last modified 2026-06-17.