fortiguard.com
https://fortiguard.com/psirt/FG-IR-20-078 CVE-2022-29056
LOW
Record summary
CVE-2022-29056 has a selected CVSS score of 3.5 (low); EIP currently links 1 repository PoC.
Description
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 22, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FortiMailBrowse Fortinet / FortiMailDefault status: unaffected | CVE List | 6.4.0 | affected |
| 6.2.1 to ≤ 6.2.4 | affected | ||
| 6.0.0 to ≤ 6.0.9 | affected | ||
| 5.4.0 to ≤ 5.4.12 | affected |
Proofs of concept
1Repository PoCs
GitHubchessredoffsec/CVE-2022-29056Repository PoCby chessredoffsecStars: 1Not analyzed2 files
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-29056