cbcvebase.
CVE-2022-35846
published 2022-10-18

CVE-2022-35846: An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.74%
50.5th percentile
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a brute force attack.

Affected

5 ranges
VendorProductVersion rangeFixed in
fortinetfortinet_fortitester
fortinetfortitester
fortinetfortitester>= 2.3.0 < 3.9.23.9.2
fortinetfortitester>= 4.0.0 < 4.2.14.2.1
fortinetfortitester>= 7.0.0 < 7.1.17.1.1

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for excessive authentication attempts against the FortiTester Telnet port, which may indicate a brute force attack targeting admin credentials
  • Focus detection on the Telnet port of FortiTester devices running versions 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, or 7.0.0 through 7.1.0
  • ·The vulnerability is specific to the Telnet port on FortiTester; no rate-limiting or lockout mechanism is enforced, enabling unlimited brute force attempts against the admin account
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.