PT-2026-24242 · Fortinet · Fortianalyzer+3

CVE-2026-22629

·

Publicado

2026-03-10

·

Atualizado

2026-03-17

CVSS v3.1

3.7

Baixa

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiAnalyzer versions 6.4 through 7.6.4 Fortinet FortiManager versions 6.4 through 7.6.4 Fortinet FortiAnalyzer Cloud versions 6.4 through 7.6.4 Fortinet FortiManager Cloud versions 6.4 through 7.6.4
Description The issue involves an insufficient restriction of excessive authentication attempts. This can allow an attacker to bypass brute-force protections by exploiting race conditions. The exploitation of race conditions increases the complexity of practical exploitation.
Recommendations Fortinet FortiAnalyzer versions 6.4 through 7.6.4: Update to a newer version that addresses this issue. Fortinet FortiManager versions 6.4 through 7.6.4: Update to a newer version that addresses this issue. Fortinet FortiAnalyzer Cloud versions 6.4 through 7.6.4: Update to a newer version that addresses this issue. Fortinet FortiManager Cloud versions 6.4 through 7.6.4: Update to a newer version that addresses this issue.

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-03212
CVE-2026-22629

Produtos afetados

Fortianalyzer
Fortianalyzer Cloud
Fortimanager
Fortimanager Cloud