Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmxq-4hqc-9hr4

Опубликовано: 24 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.

EPSS

Процентиль: 36%
0.00149
Низкий

7.5 High

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость службы FortiMail IBE (Identity Based Encryption) системы защиты электронной почты FortiMail, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 36%
0.00149
Низкий

7.5 High

CVSS3

Дефекты

CWE-338