Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6r8m-7q26-8wcc

Опубликовано: 04 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.

EPSS

Процентиль: 37%
0.00162
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1390
CWE-287

Связанные уязвимости

CVSS3: 5.3
nvd
почти 3 года назад

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.

EPSS

Процентиль: 37%
0.00162
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1390
CWE-287