PT-2023-1738 · Fortinet · Fortirecorder

Publicado

2023-03-07

·

Atualizado

2023-04-10

·

CVE-2022-41333

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FortiRecorder versions 6.4.3 and below FortiRecorder versions 6.0.11 and below
Description The issue is related to an uncontrolled resource consumption vulnerability. It may allow an unauthenticated attacker to make the device unavailable via crafted GET requests to the login authentication mechanism.
Recommendations For FortiRecorder versions 6.4.3 and below, update to a version above 6.4.3 to resolve the issue. For FortiRecorder versions 6.0.11 and below, update to a version above 6.0.11 to resolve the issue. As a temporary workaround, consider restricting access to the login authentication mechanism to minimize the risk of exploitation.

Exploit

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01329
CVE-2022-41333

Produtos afetados

Fortirecorder