CVE-2023-37934: Medium severity fortiguard fortipam vulnerability
Published Jan 10, 2024
·Updated
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service attack via sending crafted HTTP or HTTPS requests in a high frequency.
Affected Software
1 affected component
Fortinet FortiPAM>=1.0.0<1.1.0
Remediation
Information
Please upgrade to FortiPAM version 1.1.0 or above
Event History
Jan 10, 2024
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-37934?
CVE-2023-37934 is classified as a moderate severity vulnerability allowing for potential denial of service attacks.
2
How do I fix CVE-2023-37934?
To fix CVE-2023-37934, apply the latest patches provided by Fortinet for FortiPAM.
3
Who is affected by CVE-2023-37934?
CVE-2023-37934 affects all versions of FortiPAM 1.0, used by authenticated users.
4
What type of attack can be launched using CVE-2023-37934?
An authenticated attacker can launch a denial of service attack by sending high-frequency crafted HTTP or HTTPS requests.
5
Is there a workaround for CVE-2023-37934?
Currently, there are no specific workarounds documented for CVE-2023-37934 aside from applying patches.