CVE-2023-26209: Medium severity fortinet fortideceptor vulnerability
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-26209.
What is the title of this vulnerability?
The title of this vulnerability is 'A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.'
What is the severity of CVE-2023-26209?
The severity of CVE-2023-26209 is medium with a CVSS score of 5.3.
What is the affected software for CVE-2023-26209?
The affected software for CVE-2023-26209 is Fortinet FortiDeceptor version 3.1.x and before.
How can the vulnerability be exploited?
The vulnerability can be exploited by a remote unauthenticated attacker sending numerous HTTP requests to the login form, which can partially exhaust the CPU and memory.