Record summary

CVE-2022-29056 has a selected CVSS score of 3.5 (low); EIP currently links 1 repository PoC.

Description

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 22, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List6.4.0affected
6.2.1 to ≤ 6.2.4affected
6.0.0 to ≤ 6.0.9affected
5.4.0 to ≤ 5.4.12affected

Proofs of concept

1

Repository PoCs

GitHubchessredoffsec/CVE-2022-29056Repository PoCby chessredoffsecStars: 1Not analyzed2 files

5.3 KiB

GitHub

PoC details

References

2