QID 378395
Date Published: 2023-04-13
QID 378395: Fortinet FortiOS Information Disclosure Vulnerability (FG-IR-22-444)
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiOS may allow an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.10
FortiOS version 6.4.0 through 6.4.12
FortiOS 6.2 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
A Brute force attack allows attacker to obtain private user information such as usernames, passwords, passphrases, or Personal Identification Numbers (PINs).
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-444
Vendor References
- FG-IR-22-444 -
www.fortiguard.com/psirt/FG-IR-22-444
CVEs related to QID 378395
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-444 |
|