CVE-2024-26015
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N/E:F/RL:W/RC:R
- EPSS probability
- 0.47%
- CWE
- CWE-1389
- Published
- 2024-07-09
- Last modified
- 2026-03-13
Affected products
- Fortinet FortiProxy
- Fortinet FortiProxy
- Fortinet FortiProxy
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
Weakness type
Related vulnerabilities
- CVE-2026-69257 — Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
- CVE-2026-47160 — Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass
- CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
- CVE-2018-25242 — One Search 1.1.0.0 Denial of Service
- CVE-2024-6284 — Improper IPv4 and IPv6 byte order storage in github.com/google/nftables