PT-2022-5028 · Fortinet · Fortitester
Published
2022-10-10
·
Updated
2022-10-20
·
CVE-2022-35846
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiTester versions 2.3.0 through 3.9.1
FortiTester versions 4.0.0 through 4.2.0
FortiTester versions 7.0.0 through 7.1.0
Description
The issue is related to an improper restriction of excessive authentication attempts, which may allow an unauthenticated attacker to guess the credentials of an admin user via a brute force attack. This could enable a remote attacker to bypass existing security restrictions.
Recommendations
For FortiTester versions 2.3.0 through 3.9.1, consider restricting access to the Telnet port until a patch is available.
For FortiTester versions 4.0.0 through 4.2.0, consider implementing additional authentication measures to prevent brute force attacks.
For FortiTester versions 7.0.0 through 7.1.0, consider disabling the Telnet port or limiting access to it to minimize the risk of exploitation.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortitester