ZeroHour
Fortinet PSIRTpublished ()ingested

Uncontrolled Resource Consumption in SNMP

mediumAdvisoryimportance 15
AI summary · glm-5.3

Uninitialized variable flaw (CVSS 5.9) in FortiAnalyzer's SNMP daemon lets remote authenticated attackers cause denial of service via SNMP GETBULK requests.

Fortinet advisory FG-IR-26-172 describes a use of uninitialized variable vulnerability (CWE-457) in the FortiAnalyzer SNMP daemon, scored CVSSv3 5.9. A remote authenticated attacker with user-level permissions can cause a denial of service via SNMP GETBULK requests. The advisory was revised on 2026-09-08.

  • CVSSv3 5.9 uninitialized variable (CWE-457) in SNMP daemon
  • Remote authenticated attacker can cause denial of service
  • Triggered via SNMP GETBULK requests on FortiAnalyzer
Full article

CVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of service via SNMP GETBULK requests. Revised on 2026-09-08 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.