Home
LOW: 3.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:XDefault status
unaffected
6.4.0 (semver)
affected
6.3.0 (semver)
affected
6.2.0 (semver)
affected
6.1.0 (semver)
affected
6.0.0 (semver)
affected
Description
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
Problem types
Product status
6.4.0 (semver)
6.3.0 (semver)
6.2.0 (semver)
6.1.0 (semver)
6.0.0 (semver)
References
fortiguard.com/psirt/FG-IR-20-078
fortiguard.com/psirt/FG-IR-20-078