A improper restriction of excessive authentication attempts vulnerability [CWE-307] in...
Vulnerability Description
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-29056
Credits & Attribution
No credits recorded in the NVD database.
References
More from Fortinet
View All →Affected Vendor
Fortinet
View all reports →