First published: Wed Jan 10 2024(Updated: )
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service attack via sending crafted HTTP or HTTPS requests in a high frequency.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPAM | >=1.0.0<1.1.0 |
Please upgrade to FortiPAM version 1.1.0 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37934 is classified as a moderate severity vulnerability allowing for potential denial of service attacks.
To fix CVE-2023-37934, apply the latest patches provided by Fortinet for FortiPAM.
CVE-2023-37934 affects all versions of FortiPAM 1.0, used by authenticated users.
An authenticated attacker can launch a denial of service attack by sending high-frequency crafted HTTP or HTTPS requests.
Currently, there are no specific workarounds documented for CVE-2023-37934 aside from applying patches.