CVE-2023-26208
3.5LOW
Summary
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
Affected Version(s)
FortiAuthenticator 6.4.0 <= 6.4.6
FortiAuthenticator 6.3.0 <= 6.3.3
FortiAuthenticator 6.2.0 <= 6.2.1
References
CVSS V3.1
Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved