cbcvebase.
CVE-2023-26208
published 2023-03-09

CVE-2023-26208: A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote…

PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.81%
76.1th percentile
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

Affected

10 ranges
VendorProductVersion rangeFixed in
fortinetfortiauthenticator
fortinetfortiauthenticator>= 5.4.0 < 6.5.06.5.0
fortinetfortiauthenticator6.0.0 – 6.0.7
fortinetfortiauthenticator6.1.0 – 6.1.2
fortinetfortiauthenticator6.2.0 – 6.2.1
fortinetfortiauthenticator6.3.0 – 6.3.3
fortinetfortiauthenticator6.4.0 – 6.4.6
fortinetfortideceptor
fortinetfortimail
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.