PT-2023-7425 · Fortinet · Fortiproxy+1

CVE-2022-43947

·

Publicado

2023-04-11

·

Atualizado

2023-04-18

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.2.0 through 7.2.3 FortiOS versions prior to 7.0.10 FortiProxy versions 7.2.0 through 7.2.2 FortiProxy versions prior to 7.0.8
Description The issue is related to an improper restriction of excessive authentication attempts in the administrative interface of FortiOS and FortiProxy, allowing an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions.
Recommendations For FortiOS versions 7.2.0 through 7.2.3, update to a version that includes the fix for this issue. For FortiOS versions prior to 7.0.10, update to a version that includes the fix for this issue. For FortiProxy versions 7.2.0 through 7.2.2, update to a version that includes the fix for this issue. For FortiProxy versions prior to 7.0.8, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the administrative interface to minimize the risk of exploitation.

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08462
CVE-2022-43947

Produtos afetados

Fortios
Fortiproxy