QID 44033
Date Published: 2023-05-31
QID 44033: Fortinet FortiOS Improper Access Control Vulnerability (FG-IR-22-444) (Unauthenticated Check)
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiOS may allow an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions.
Affected Versions:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.10
FortiOS version 6.4.0 through 6.4.12
FortiOS 6.2 all versions
QID Detection Logic (NoAuth):
Detection checks for vulnerable version of FortiOS.
A Brute force attack allows attacker to obtain private user information such as usernames, passwords, passphrases, or Personal Identification Numbers (PINs).
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-22-444
Vendor References
- FG-IR-22-444 -
www.fortiguard.com/psirt/FG-IR-22-444
CVEs related to QID 44033
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-444 |
|