PT-2023-3232 · Fortinet · Fortisiem

Publicado

2023-06-12

·

Atualizado

2023-06-17

·

CVE-2022-43949

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiSIEM versions prior to 6.7.1
Description The issue is related to the use of a broken or risky cryptographic algorithm, allowing a remote unauthenticated attacker to perform brute force attacks on GUI endpoints by taking advantage of outdated hashing methods. This can potentially allow an attacker to disclose protected information.
Recommendations For Fortinet FortiSIEM versions prior to 6.7.1, update to version 6.7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to GUI endpoints to minimize the risk of exploitation.

Correção

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03353
CVE-2022-43949

Produtos afetados

Fortisiem