A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods.
2023-06-13T09:15:16.027
2024-11-21T07:27:23.920
Modified
CVSSv3.1: 6.2 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisiem | ≤ 5.3.3 | Yes |
Application | fortinet | fortisiem | ≤ 6.3.3 | Yes |
Application | fortinet | fortisiem | ≤ 6.6.3 | Yes |
Application | fortinet | fortisiem | 5.4.0 | Yes |
Application | fortinet | fortisiem | 6.1.0 | Yes |
Application | fortinet | fortisiem | 6.1.1 | Yes |
Application | fortinet | fortisiem | 6.1.2 | Yes |
Application | fortinet | fortisiem | 6.2.0 | Yes |
Application | fortinet | fortisiem | 6.2.1 | Yes |
Application | fortinet | fortisiem | 6.4.0 | Yes |
Application | fortinet | fortisiem | 6.4.1 | Yes |
Application | fortinet | fortisiem | 6.4.2 | Yes |
Application | fortinet | fortisiem | 6.5.0 | Yes |
Application | fortinet | fortisiem | 6.5.1 | Yes |
Application | fortinet | fortisiem | 6.7.0 | Yes |
Application | fortinet | fortisiem | 6.7.1 | Yes |