Improper Authentication Attempts in Fortinet FortiAuthenticator Products
CVE-2023-26208
3.5LOW
What is CVE-2023-26208?
A vulnerability exists in Fortinet FortiAuthenticator products that allows a remote unauthenticated attacker to exploit improper restrictions on excessive authentication attempts. By sending a high volume of HTTP requests to the login form, an attacker can partially exhaust the CPU and memory resources, potentially leading to service disruption. This vulnerability affects FortiAuthenticator versions 6.4.x and earlier, making it crucial for users to apply appropriate security measures and updates.
Affected Version(s)
FortiAuthenticator 6.4.0 <= 6.4.6
FortiAuthenticator 6.3.0 <= 6.3.3
FortiAuthenticator 6.2.0 <= 6.2.1