CVE-2022-43949: High severity fortinet fortisiem windows agent vulnerability
A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-43949?
CVE-2022-43949 is a vulnerability that allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints in Fortinet FortiSIEM before version 6.7.1.
How severe is CVE-2022-43949?
CVE-2022-43949 has a severity score of 7.5 (high).
Which software versions are affected by CVE-2022-43949?
Fortinet FortiSIEM versions 5.3.0 to 5.3.3, 6.3.0 to 6.3.3, and 6.6.0 to 6.6.3 are affected by CVE-2022-43949.
How can I fix CVE-2022-43949?
To fix CVE-2022-43949, upgrade your Fortinet FortiSIEM software to version 6.7.1 or later.
Where can I find more information about CVE-2022-43949?
You can find more information about CVE-2022-43949 on the Fortinet FortiGuard website: https://fortiguard.com/psirt/FG-IR-22-259