cbcvebase.
CVE-2024-46667
published 2025-01-14

CVE-2024-46667: A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
43.3th percentile
A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connections.

Affected

14 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortisiem
fortinetfortisiem
fortinetfortisiem5.3.0 – 5.3.3
fortinetfortisiem6.1.0 – 6.1.2
fortinetfortisiem6.2.0 – 6.2.1
fortinetfortisiem6.3.0 – 6.3.3
fortinetfortisiem6.4.0 – 6.4.4
fortinetfortisiem6.5.0 – 6.5.3
fortinetfortisiem6.6.0 – 6.6.5
fortinetfortisiem6.7.0 – 6.7.9
fortinetfortisiem7.0.0 – 7.0.3
fortinetfortisiem>= 7.1.0 < 7.1.67.1.6
fortinetfortisiem7.1.0 – 7.1.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.