Sceawere
Vulnerability Detail
CVE-2026-71408UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FortiOS Resource Exhaustion Denial of Service Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Fortinet
- Product
- FortiOS
- Attack Type
- Denial of service
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-12T13:17:25.677Z",
"pubdate": "2026-08-12T13:17:25.677Z",
"executiveSummary": "An allocation of resources without limits or throttling vulnerability exists within Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, and FortiOS 7.2 all versions.\nThis vulnerability allows an unauthenticated remote attacker to trigger a denial of service (DoS) state on vulnerable targets by exhausting critical system resources.\nThe flaw stems from insufficient rate limiting, resource bounds, or throttling mechanisms during the handling of incoming requests or connection setups.\nSuccessful exploitation results in severe performance degradation, service unresponsiveness, or complete system crashes, rendering the affected network security device incapable of processing legitimate traffic and network functions.\nThe risk implication is critical, as it directly impacts perimeter security, availability, and network operations.\nAttackers do not require prior privileges or complex authentication to initiate the attack, provided they can reach the vulnerable service endpoint over the network.\nMitigation requires applying vendor-supplied software upgrades or implementing strict perimeter controls and rate-limiting policies where applicable.",
"technicalDetails": "The vulnerability is classified as an allocation of resources without limits or throttling, occurring due to the absence of adequate input validation, resource quotas, or rate-limiting controls in the core processing logic of the affected FortiOS versions.\nSpecifically, the vulnerable component fails to properly restrict the quantity of resources—such as memory buffers, CPU cycles, or concurrent connection sockets—that can be requested or allocated during specific transaction phases.\nAffected software versions comprise Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, and FortiOS 7.2 all versions.\nThe attack vector involves sending a continuous stream of specially crafted requests or establishing a high volume of unthrottled connections directly to the vulnerable interface or service.\nBecause the application layer or network stack does not enforce strict allocation thresholds or implement exponential backoff and connection throttling, every incoming request forces the system to continuously allocate dynamic memory or process intensive routines without releasing or capping utilization.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies the exposed network service endpoint on the FortiOS device. Second, the attacker transmits a sustained flood of resource-intensive connection requests or payload structures designed to maximize resource consumption. Third, the system continuously honors these allocation requests until internal memory pools, file descriptors, or process queues reach maximum capacity. Fourth, resource exhaustion triggers cascading failures across dependent system daemons, leading to kernel panics, unresponsive management planes, or complete denial of service.\nAuthentication and privilege requirements are minimal or entirely absent, allowing remote unauthenticated actors to trigger the condition directly across the network.\nThe post-exploitation impact is strictly focused on availability, manifesting as service disruption, dropped client connections, inability for administrators to access the administrative GUI or CLI, and potential requirements for a hard physical or remote power cycle to restore normal device operations."
}