Lucene search

K
nvd[email protected]NVD:CVE-2022-35846
HistoryOct 18, 2022 - 2:15 p.m.

CVE-2022-35846

2022-10-1814:15:09
CWE-307
web.nvd.nist.gov
5
cve-2022-35846
fortitester
telnet
brute force

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.3%

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a brute force attack.

Affected configurations

Nvd
Node
fortinetfortitesterRange2.3.03.9.2
OR
fortinetfortitesterRange4.0.04.2.1
OR
fortinetfortitesterRange7.0.07.1.1
VendorProductVersionCPE
fortinetfortitester*cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.3%

Related for NVD:CVE-2022-35846