CVE-2022-42478

EUVD-2022-45548
An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:U/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
fortinetfortisiem
5.1.0 ≤
𝑥
≤ 5.1.3
fortinetfortisiem
5.3.0 ≤
𝑥
≤ 5.3.3
fortinetfortisiem
6.3.0 ≤
𝑥
≤ 6.3.3
fortinetfortisiem
5.2.1
fortinetfortisiem
5.2.2
fortinetfortisiem
5.2.5
fortinetfortisiem
5.2.6
fortinetfortisiem
5.2.7
fortinetfortisiem
5.2.8
fortinetfortisiem
5.4.0
fortinetfortisiem
6.1.0
fortinetfortisiem
6.1.1
fortinetfortisiem
6.1.2
fortinetfortisiem
6.2.0
fortinetfortisiem
6.2.1
fortinetfortisiem
6.4.0
fortinetfortisiem
6.4.1
fortinetfortisiem
6.4.2
fortinetfortisiem
6.5.0
fortinetfortisiem
6.5.1
fortinetfortisiem
6.6.0
fortinetfortisiem
6.6.1
fortinetfortisiem
6.6.2
fortinetfortisiem
6.6.3
fortinetfortisiem
6.7.0
𝑥
= Vulnerable software versions