CVE-2022-43947
11.04.2023, 17:15
Animproper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions.Enginsight
Vendor | Product | Version |
---|---|---|
fortinet | fortiproxy | 1.0.0 ≤ 𝑥 ≤ 2.0.9 |
fortinet | fortiproxy | 7.0.0 ≤ 𝑥 < 7.0.8 |
fortinet | fortiproxy | 7.2.0 ≤ 𝑥 < 7.2.2 |
fortinet | fortios | 6.2.0 ≤ 𝑥 < 6.4.13 |
fortinet | fortios | 7.0.0 ≤ 𝑥 < 7.0.11 |
fortinet | fortios | 7.2.0 ≤ 𝑥 < 7.2.4 |
𝑥
= Vulnerable software versions