Improper Authentication Attempts in Fortinet FortiAuthenticator Products
CVE-2023-26208
3.5LOW
Summary
A vulnerability exists in Fortinet FortiAuthenticator products that allows a remote unauthenticated attacker to exploit improper restrictions on excessive authentication attempts. By sending a high volume of HTTP requests to the login form, an attacker can partially exhaust the CPU and memory resources, potentially leading to service disruption. This vulnerability affects FortiAuthenticator versions 6.4.x and earlier, making it crucial for users to apply appropriate security measures and updates.
Affected Version(s)
FortiAuthenticator 6.4.0 <= 6.4.6
FortiAuthenticator 6.3.0 <= 6.3.3
FortiAuthenticator 6.2.0 <= 6.2.1
References
CVSS V3.1
Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved