An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.
2023-03-07T17:15:12.233
2024-11-21T07:23:04.350
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fortinet | fortirecorder_firmware | ≤ 6.0.11 | Yes |
Operating System | fortinet | fortirecorder_firmware | ≤ 6.4.3 | Yes |