Use of Risky Cryptographic Algorithm in Fortinet FortiSIEM Software
CVE-2022-43949

5.9MEDIUM

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
13 June 2023

Summary

A vulnerability in Fortinet's FortiSIEM software arises from the use of a flawed cryptographic algorithm. This issue allows attackers, without authentication, to exploit GUI endpoints through brute force attacks. The problem is exacerbated by the reliance on outdated hashing methods, exposing the system to potential unauthorized access. Users are urged to update to version 6.7.1 or later to mitigate this risk.

Affected Version(s)

FortiSIEM 6.7.0 <= 6.7.1

FortiSIEM 6.6.0 <= 6.6.3

FortiSIEM 6.5.0 <= 6.5.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.