Home
MEDIUM: 6.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:RDefault status
unaffected
6.4.0 (semver)
affected
6.0.0 (semver)
affected
Description
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.
Problem types
Product status
6.4.0 (semver)
6.0.0 (semver)
References
fortiguard.com/psirt/FG-IR-22-388
packetstormsecurity.com/...rder-6.4.3-Denial-Of-Service.html
fortiguard.com/psirt/FG-IR-22-388
packetstormsecurity.com/...rder-6.4.3-Denial-Of-Service.html