Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jf4v-mhj5-v7mx

Опубликовано: 14 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the affected endpoints via repeated login attempts.

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the affected endpoints via repeated login attempts.

EPSS

Процентиль: 43%
0.00206
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 5.6
nvd
около 2 лет назад

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the affected endpoints via repeated login attempts.

EPSS

Процентиль: 43%
0.00206
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-307