Use of Risky Cryptographic Algorithm in Fortinet FortiSIEM Software
CVE-2022-43949
5.9MEDIUM
Summary
A vulnerability in Fortinet's FortiSIEM software arises from the use of a flawed cryptographic algorithm. This issue allows attackers, without authentication, to exploit GUI endpoints through brute force attacks. The problem is exacerbated by the reliance on outdated hashing methods, exposing the system to potential unauthorized access. Users are urged to update to version 6.7.1 or later to mitigate this risk.
Affected Version(s)
FortiSIEM 6.7.0 <= 6.7.1
FortiSIEM 6.6.0 <= 6.6.3
FortiSIEM 6.5.0 <= 6.5.1
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved