cbcvebase.
CVE-2023-26209
published 2023-03-09

CVE-2023-26209: A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated…

PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.75%
75.2th percentile
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

Affected

11 ranges
VendorProductVersion rangeFixed in
fortinetfortiauthenticator
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor>= 1.0.0 < 3.2.03.2.0
fortinetfortideceptor1.0.0 – 1.0.1
fortinetfortideceptor3.0.0 – 3.0.2
fortinetfortideceptor3.1.0 – 3.1.1
fortinetfortimail
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.