AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-26008

MEDIUM · CVSS 5.3 EPSS 0.44%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-10-14 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. It affects FortiOS. Exploitation may require the attacker to be authenticated.

CVE
CVE-2024-26008
Severity
MEDIUM
CVSS
5.3
EPSS
0.44%
FortiOS

Original NVD Description

An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests.

Related CVEs

Other vulnerabilities affecting the same vendor(s)