An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
2021-08-04T19:15:08.313
2024-11-21T05:49:33.153
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiauthenticator | ≤ 4.3.4 | Yes |
Application | fortinet | fortiauthenticator | ≤ 5.5.0 | Yes |
Application | fortinet | fortiauthenticator | < 6.0.6 | Yes |
Application | fortinet | fortisandbox | < 3.0.7 | Yes |
Application | fortinet | fortisandbox | < 3.1.5 | Yes |
Application | fortinet | fortisandbox | < 3.2.2 | Yes |