CVE-2024-46669: Fortinet FortiOS

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.

Affected products

  • Fortinet FortiOS: from 7.2.0, before 7.4.5 (fixed in 7.4.5)

Published 2025-01-14. Last modified 2026-06-17.