PT-2026-24242 · Fortinet · Fortianalyzer+3
CVE-2026-22629
·
Publicado
2026-03-10
·
Atualizado
2026-03-17
CVSS v3.1
3.7
Baixa
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiAnalyzer versions 6.4 through 7.6.4
Fortinet FortiManager versions 6.4 through 7.6.4
Fortinet FortiAnalyzer Cloud versions 6.4 through 7.6.4
Fortinet FortiManager Cloud versions 6.4 through 7.6.4
Description
The issue involves an insufficient restriction of excessive authentication attempts. This can allow an attacker to bypass brute-force protections by exploiting race conditions. The exploitation of race conditions increases the complexity of practical exploitation.
Recommendations
Fortinet FortiAnalyzer versions 6.4 through 7.6.4: Update to a newer version that addresses this issue.
Fortinet FortiManager versions 6.4 through 7.6.4: Update to a newer version that addresses this issue.
Fortinet FortiAnalyzer Cloud versions 6.4 through 7.6.4: Update to a newer version that addresses this issue.
Fortinet FortiManager Cloud versions 6.4 through 7.6.4: Update to a newer version that addresses this issue.
Correção
Improper Restriction of Excessive Authentication Attempts
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fortianalyzer
Fortianalyzer Cloud
Fortimanager
Fortimanager Cloud