CVE-2023-26208: Medium severity fortinet fortiauthenticator vulnerability
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-26208.
What is the title of the vulnerability?
The title of the vulnerability is 'A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before'.
How does the vulnerability affect the Fortinet FortiAuthenticator?
The vulnerability allows a remote unauthenticated attacker to partially exhaust CPU and memory by sending numerous HTTP requests to the login form.
Which version of Fortinet FortiAuthenticator is affected by the vulnerability?
Fortinet FortiAuthenticator versions 6.4.x and before are affected by the vulnerability.
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 5.3.
How can I fix the vulnerability?
To fix the vulnerability, update your Fortinet FortiAuthenticator to a version above 6.5.0.
Is there any additional reference for the vulnerability?
You can find additional reference for the vulnerability at https://fortiguard.com/psirt/FG-IR-20-078.