CVE-2022-43947
published 2023-04-11CVE-2022-43947: An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.40%
32.6th percentile
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.2.0 < 6.4.13 | 6.4.13 |
| fortinet | fortios | 6.2.0 – 6.2.13 | — |
| fortinet | fortios | 6.4.0 – 6.4.12 | — |
| fortinet | fortios | >= 7.0.0 < 7.0.11 | 7.0.11 |
| fortinet | fortios | 7.0.0 – 7.0.10 | — |
| fortinet | fortios | >= 7.2.0 < 7.2.4 | 7.2.4 |
| fortinet | fortios | 7.2.0 – 7.2.3 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | 1.0.0 – 2.0.9 | — |
| fortinet | fortiproxy | 1.1.0 – 1.1.6 | — |
| fortinet | fortiproxy | 1.2.0 – 1.2.13 | — |
| fortinet | fortiproxy | 2.0.0 – 2.0.12 | — |
| fortinet | fortiproxy | >= 7.0.0 < 7.0.8 | 7.0.8 |
| fortinet | fortiproxy | 7.0.0 – 7.0.7 | — |
| fortinet | fortiproxy | >= 7.2.0 < 7.2.2 | 7.2.2 |
| fortinet | fortiproxy | 7.2.0 – 7.2.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-89mj-q662-x3r3: An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7
ghsa_unreviewed·2023-07-06
CVE-2022-43947 [HIGH] CWE-307 GHSA-89mj-q662-x3r3: An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions.
CISA ICS
Siemens RUGGEDCOM APE1808 with Fortigate NGFW Devices
cisa_ics·2024-03-14
Siemens RUGGEDCOM APE1808 with Fortigate NGFW Devices
ICS Advisory
##
Siemens RUGGEDCOM APE1808 with Fortigate NGFW Devices
Release DateMarch 14, 2024
Alert CodeICSA-24-074-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM APE1808 devices
- Vulnerabilities: Improper Certificate Validation, Cleartext Transmission of Sensitive Information, Path Traversal, Exposure of Sensitive Information to an Unauthorized
Fortinet
Anti brute-force bypass in administrative interface
vendor_fortinet·2023-04-11·CVSS 5.0
CVE-2022-43947 [MEDIUM] CWE-307 Anti brute-force bypass in administrative interface
FG-IR-22-444: Anti brute-force bypass in administrative interface
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions.
CVEs: CVE-2022-43947
CWEs: CWE-307
CVSS: 5.0 (medium)
Affected products: FortiOS, FortiProxy, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-11
Published