Denial of Service in TLS-SYSLOG handler

Summary

An allocation of resources without limits or throttling [CWE-770] in FortiSIEM TLS-SYSLOG may allow an attacker to deny valid TLS traffic via consuming all allotted connections.

Version Affected Solution
FortiSIEM 7.3 Not affected Not Applicable
FortiSIEM 7.2 Not affected Not Applicable
FortiSIEM 7.1 7.1.0 through 7.1.5 Upgrade to 7.1.6 or above
FortiSIEM 7.0 7.0 all versions Migrate to a fixed release
FortiSIEM 6.7 6.7 all versions Migrate to a fixed release
FortiSIEM 6.6 6.6 all versions Migrate to a fixed release
FortiSIEM 6.5 6.5 all versions Migrate to a fixed release
FortiSIEM 6.4 6.4 all versions Migrate to a fixed release
FortiSIEM 6.3 6.3 all versions Migrate to a fixed release
FortiSIEM 6.2 6.2 all versions Migrate to a fixed release
FortiSIEM 6.1 6.1 all versions Migrate to a fixed release
FortiSIEM 5.4 5.4 all versions Migrate to a fixed release
FortiSIEM 5.3 5.3 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank James Reno from Nuspire for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication