CVE-2023-26209

3.5LOW

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
9 March 2023

Summary

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

Affected Version(s)

FortiDeceptor 3.1.0 <= 3.1.1

FortiDeceptor 3.0.0 <= 3.0.2

FortiDeceptor 2.1.0

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.