cbcvebase.
CVE-2022-29056
published 2023-03-09

CVE-2022-29056: A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before…

PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.81%
76.1th percentile
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

Affected

10 ranges
VendorProductVersion rangeFixed in
fortinetfortiauthenticator
fortinetfortideceptor
fortinetfortimail
fortinetfortimail
fortinetfortimail5.4.0 – 5.4.12
fortinetfortimail>= 6.0.0 < 6.0.106.0.10
fortinetfortimail6.0.0 – 6.0.9
fortinetfortimail>= 6.2.1 < 6.2.56.2.5
fortinetfortimail6.2.1 – 6.2.4
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.