Improper Authentication Control in FortiSIEM by Fortinet
CVE-2022-42478
8.1HIGH
Summary
An improper restriction of excessive authentication attempts in FortiSIEM versions prior to 7.0.0 could allow non-privileged users to launch brute force attacks on multiple endpoints. This vulnerability highlights potential security flaws in user authentication mechanisms, making it critical for organizations relying on FortiSIEM to update to the latest versions and implement additional security measures to protect sensitive endpoints.
Affected Version(s)
FortiSIEM 6.7.0
FortiSIEM 6.6.0 <= 6.6.3
FortiSIEM 6.5.0 <= 6.5.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved