CVE-2024-26008
published 2025-10-14CVE-2024-26008: An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.44%
35.5th percentile
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.2.0 < 7.2.8 | 7.2.8 |
| fortinet | fortios | 6.2.0 – 6.2.17 | — |
| fortinet | fortios | 6.4.0 – 6.4.16 | — |
| fortinet | fortios | 7.0.0 – 7.0.18 | — |
| fortinet | fortios | 7.2.0 – 7.2.7 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortios | 7.4.0 – 7.4.3 | — |
| fortinet | fortipam | — | — |
| fortinet | fortipam | — | — |
| fortinet | fortipam | >= 1.0.0 < 1.3.0 | 1.3.0 |
| fortinet | fortipam | 1.0.0 – 1.0.3 | — |
| fortinet | fortipam | 1.1.0 – 1.1.2 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | >= 1.2.0 < 7.2.10 | 7.2.10 |
| fortinet | fortiproxy | 1.2.0 – 1.2.13 | — |
| fortinet | fortiproxy | 2.0.0 – 2.0.14 | — |
| fortinet | fortiproxy | 7.0.0 – 7.0.22 | — |
| fortinet | fortiproxy | 7.2.0 – 7.2.9 | — |
| fortinet | fortiproxy | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortiproxy | 7.4.0 – 7.4.3 | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | >= 7.0.0 < 7.0.4 | 7.0.4 |
| fortinet | fortiswitchmanager | 7.0.0 – 7.0.3 | — |
| fortinet | fortiswitchmanager | >= 7.2.0 < 7.2.4 | 7.2.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qh97-826g-4v22: An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7
ghsa_unreviewed·2025-10-14
CVE-2024-26008 [MEDIUM] CWE-754 GHSA-qh97-826g-4v22: An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests.
Fortinet
FGFM protocol allows unauthenticated reset of the connection
vendor_fortinet·2025-10-14·CVSS 5.3
CVE-2024-26008 [MEDIUM] CWE-754 FGFM protocol allows unauthenticated reset of the connection
FG-IR-24-041: FGFM protocol allows unauthenticated reset of the connection
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests.
CVEs: CVE-2024-26008
CWEs: CWE-754
CVSS: 5.3 (medium)
Affected products: FortiOS, FortiPAM, FortiProxy, FortiSwitchManager, FortiSwitchmanager
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-14
Published