Improper Authentication Control in FortiSIEM by Fortinet
CVE-2022-42478

8.1HIGH

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
13 June 2023

Summary

An improper restriction of excessive authentication attempts in FortiSIEM versions prior to 7.0.0 could allow non-privileged users to launch brute force attacks on multiple endpoints. This vulnerability highlights potential security flaws in user authentication mechanisms, making it critical for organizations relying on FortiSIEM to update to the latest versions and implement additional security measures to protect sensitive endpoints.

Affected Version(s)

FortiSIEM 6.7.0

FortiSIEM 6.6.0 <= 6.6.3

FortiSIEM 6.5.0 <= 6.5.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.