Excessive Authentication Attempts in FortiTester Products by Fortinet
CVE-2022-35846
8.1HIGH
What is CVE-2022-35846?
FortiTester products have a vulnerability that improperly restricts excessive authentication attempts, allowing unauthenticated attackers to execute brute force attacks to guess admin credentials. This flaw affects multiple versions, emphasizing the need for users to limit the access and utilize additional security measures to protect their administrative interfaces.
Affected Version(s)
Fortinet FortiTester FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0