Home

Description

An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.

PUBLISHED Reserved 2022-09-23 | Published 2023-03-07 | Updated 2025-02-13 | Assigner fortinet




MEDIUM: 6.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R

Problem types

Denial of service

Product status

Default status
unaffected

6.4.0 (semver)
affected

6.0.0 (semver)
affected

References

fortiguard.com/psirt/FG-IR-22-388

packetstormsecurity.com/...rder-6.4.3-Denial-Of-Service.html

fortiguard.com/psirt/FG-IR-22-388

packetstormsecurity.com/...rder-6.4.3-Denial-Of-Service.html

cve.org (CVE-2022-41333)

nvd.nist.gov (CVE-2022-41333)