An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force attack on the affected endpoints via repeated login attempts.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-49874 | An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force attack on the affected endpoints via repeated login attempts. |
Fixes
Solution
Please upgrade to FortiMail version 7.4.1 or above Please upgrade to FortiMail version 7.2.5 or above Please upgrade to FortiMail version 7.0.7 or above Please upgrade to FortiMail version 6.4.9 or above
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-287 |
|
History
No history.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-30T18:14:28.885Z
Reserved: 2023-10-09T08:01:29.296Z
Link: CVE-2023-45582
Updated: 2024-08-02T20:21:16.739Z
Status : Modified
Published: 2023-11-14T18:15:55.017
Modified: 2024-11-21T08:27:00.303
Link: CVE-2023-45582
No data.
OpenCVE Enrichment
No data.
EUVD