CVE-2022-41333

An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
fortinetCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
Affected Products (NVD)
VendorProductVersion
fortinetfortirecorder_firmware
6.0.0 ≤
𝑥
≤ 6.0.11
fortinetfortirecorder_firmware
6.4.0 ≤
𝑥
≤ 6.4.3
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
fortinetfortirecorder
6.4.0 ≤
𝑥
≤ 6.4.3
CNA
fortinetfortirecorder
6.0.0 ≤
𝑥
≤ 6.0.11
CNA