Fiche vulnérabilité
CVE-2022-41333 : faille moyenne Fortinet FortiRecorder (CVSS 6.8)
Description
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.
En bref
- Sévérité
- Moyenne (CVSS 6.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 mars 2023
- Dernière mise à jour
- 13 févr. 2025
Produits concernés
- Fortinet FortiRecorder
Correctif et mesures
Please upgrade to FortiRecorder version 7.0.0 or above Please upgrade to FortiRecorder version 6.4.4 or above Please upgrade to FortiRecorder version 6.0.12 or above
Preuves de concept publiques
Code tiers non vérifié : à n’exécuter qu’en environnement isolé.