packetstormsecurity.com
http://packetstormsecurity.com/files/171766/FortiRecorder-6.4.3-Denial-Of-Service.html CVE-2022-41333
MEDIUM
FortiRecorder 6.4.3 - Denial of Service
Record summary
CVE-2022-41333 has a selected CVSS score of 6.8 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FortiRecorderBrowse Fortinet / FortiRecorderDefault status: unaffected | CVE List | 6.4.0 to ≤ 6.4.3 | affected |
| 6.0.0 to ≤ 6.0.11 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBFortiRecorder 6.4.3 - Denial of ServiceExploitDB exploitby Mohammed AdelNot analyzed1 file
Repository PoCs
GitHubpolar0x/CVE-2022-41333Repository PoCby polar0xStars: 0Not analyzed4 files
References
3fortiguard.com
https://fortiguard.com/psirt/FG-IR-22-388 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-41333