Sceawere

Vulnerability Detail

CVE-2026-71408UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FortiOS Resource Exhaustion Denial of Service Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Fortinet
Product
FortiOS
Attack Type
Denial of service
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-12T13:17:25.677Z",
  "pubdate": "2026-08-12T13:17:25.677Z",
  "executiveSummary": "An allocation of resources without limits or throttling vulnerability exists within Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, and FortiOS 7.2 all versions.\nThis vulnerability allows an unauthenticated remote attacker to trigger a denial of service (DoS) state on vulnerable targets by exhausting critical system resources.\nThe flaw stems from insufficient rate limiting, resource bounds, or throttling mechanisms during the handling of incoming requests or connection setups.\nSuccessful exploitation results in severe performance degradation, service unresponsiveness, or complete system crashes, rendering the affected network security device incapable of processing legitimate traffic and network functions.\nThe risk implication is critical, as it directly impacts perimeter security, availability, and network operations.\nAttackers do not require prior privileges or complex authentication to initiate the attack, provided they can reach the vulnerable service endpoint over the network.\nMitigation requires applying vendor-supplied software upgrades or implementing strict perimeter controls and rate-limiting policies where applicable.",
  "technicalDetails": "The vulnerability is classified as an allocation of resources without limits or throttling, occurring due to the absence of adequate input validation, resource quotas, or rate-limiting controls in the core processing logic of the affected FortiOS versions.\nSpecifically, the vulnerable component fails to properly restrict the quantity of resources—such as memory buffers, CPU cycles, or concurrent connection sockets—that can be requested or allocated during specific transaction phases.\nAffected software versions comprise Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, and FortiOS 7.2 all versions.\nThe attack vector involves sending a continuous stream of specially crafted requests or establishing a high volume of unthrottled connections directly to the vulnerable interface or service.\nBecause the application layer or network stack does not enforce strict allocation thresholds or implement exponential backoff and connection throttling, every incoming request forces the system to continuously allocate dynamic memory or process intensive routines without releasing or capping utilization.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies the exposed network service endpoint on the FortiOS device. Second, the attacker transmits a sustained flood of resource-intensive connection requests or payload structures designed to maximize resource consumption. Third, the system continuously honors these allocation requests until internal memory pools, file descriptors, or process queues reach maximum capacity. Fourth, resource exhaustion triggers cascading failures across dependent system daemons, leading to kernel panics, unresponsive management planes, or complete denial of service.\nAuthentication and privilege requirements are minimal or entirely absent, allowing remote unauthenticated actors to trigger the condition directly across the network.\nThe post-exploitation impact is strictly focused on availability, manifesting as service disruption, dropped client connections, inability for administrators to access the administrative GUI or CLI, and potential requirements for a hard physical or remote power cycle to restore normal device operations."
}
CVE-2026-71408: FortiOS Resource Exhaustion Denial of Service Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere