CVE-2022-35846: Critical severity fortinet fortitester vulnerability
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a brute force attack.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
This vulnerability is identified by CVE-2022-35846.
What is the severity rating of CVE-2022-35846?
CVE-2022-35846 has a severity rating of 9.8 (Critical).
What is the affected software for CVE-2022-35846?
FortiTester Telnet port versions 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, and 7.0.0 through 7.1.0 are affected by this vulnerability.
How can an attacker exploit CVE-2022-35846?
An attacker can exploit CVE-2022-35846 by using a brute force attack to guess the credentials of an admin user on FortiTester.
Where can I find more information about CVE-2022-35846?
You can find more information about CVE-2022-35846 at the FortiGuard website: https://fortiguard.com/psirt/FG-IR-22-244