An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force attack on the affected endpoints via repeated login attempts.
2023-11-14T18:15:55.017
2024-11-21T08:27:00.303
Modified
CVSSv3.1: 5.6 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortimail | ≤ 6.2.9 | Yes |
Application | fortinet | fortimail | ≤ 6.4.8 | Yes |
Application | fortinet | fortimail | ≤ 7.0.6 | Yes |
Application | fortinet | fortimail | ≤ 7.2.4 | Yes |
Application | fortinet | fortimail | 7.4.0 | Yes |