CVE-2023-45582

5.6MEDIUM

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated

Published: 11/14/2023Updated: 11/21/2024

Description

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the affected endpoints via repeated login attempts.

AI AnalysisPowered by AI

Affected Products

fortinetfortimail
fortinetfortimail
fortinetfortimail
fortinetfortimail
fortinetfortimail
7.4.0

References