Multipart Form Data Denial of Service

Summary

An allocation of resources without limits or throttling vulnerability [CWE-770] in some FortiOS API endpoints may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.

Version Affected Solution
FortiOS 7.6 Not affected Not Applicable
FortiOS 7.4 7.4.0 through 7.4.4 Upgrade to 7.4.5 or above
FortiOS 7.2 7.2.0 through 7.2.8 Upgrade to 7.2.9 or above
FortiOS 7.0 7.0.0 through 7.0.15 Upgrade to 7.0.16 or above
FortiOS 6.4 6.4.0 through 6.4.15 Upgrade to 6.4.16 or above
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Acknowledgement

Fortinet is pleased to thank Ben Barnea from Akamai for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication