An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions.
2023-04-11T17:15:07.693
2024-11-21T07:27:23.687
Modified
CVSSv3.1: 5.0 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiproxy | ≤ 2.0.9 | Yes |
Application | fortinet | fortiproxy | < 7.0.8 | Yes |
Application | fortinet | fortiproxy | < 7.2.2 | Yes |
Operating System | fortinet | fortios | < 6.4.13 | Yes |
Operating System | fortinet | fortios | < 7.0.11 | Yes |
Operating System | fortinet | fortios | < 7.2.4 | Yes |