CVE-2022-29056

3.5LOW

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
9 March 2023

Summary

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

Affected Version(s)

FortiMail 6.4.0

FortiMail 6.2.1 <= 6.2.4

FortiMail 6.0.0 <= 6.0.9

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.