CVE-2023-26208

3.5LOW

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
9 March 2023

Summary

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

Affected Version(s)

FortiAuthenticator 6.4.0 <= 6.4.6

FortiAuthenticator 6.3.0 <= 6.3.3

FortiAuthenticator 6.2.0 <= 6.2.1

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.