Improper Authentication Limitations in Fortinet FortiDeceptor Product
CVE-2023-26209
3.5LOW
Summary
An improper restriction of excessive authentication attempts in Fortinet FortiDeceptor allows remote unauthenticated attackers to send numerous HTTP requests to the login form. This can lead to partial exhaustion of the system's CPU and memory resources, potentially disrupting its availability. Organizations using FortiDeceptor 3.1.x and earlier versions should take immediate action to patch this vulnerability to mitigate the impact of such attacks.
Affected Version(s)
FortiDeceptor 3.1.0 <= 3.1.1
FortiDeceptor 3.0.0 <= 3.0.2
FortiDeceptor 2.1.0
References
CVSS V3.1
Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved