Impact
The vulnerability is an uncontrolled resource allocation flaw in Fortinet FortiOS. When exploited, an attacker can cause the system to hoard memory or other resources without limits, which can lead to a denial of service. The weakness is a classic example of a resource exhaustion flaw, identified as CWE‑770. The impact is a loss of availability, potentially affecting all users on the compromised device.
Affected Systems
Affected products are Fortinet FortiOS firmware versions 7.6.0 through 7.6.6, all releases of 7.4, and all releases of 7.2. Users running these firmware versions should confirm their current build and plan to update to a non‑affected version.
Risk and Exploitability
The CVSS base score is 5, indicating medium severity. The EPSS score is not available, so the likelihood of exploitation in the wild is unknown. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The attack vector is not explicitly described in the available data; it is inferred that it could be triggered via specific network traffic that initiates resource allocation, such as malformed requests or excessive connection attempts.
OpenCVE Enrichment