Bruteforce of Exposed Endpoints

Summary

An improper restriction of excessive authentication attempts [CWE-307] in FortiSIEM may allow a unauthenticated user with access to several endpoints to perform a brute force attack on these endpoints.

Version Affected Solution
FortiSIEM 7.0 Not affected Not Applicable
FortiSIEM 6.7 6.7.0 Upgrade to 6.7.1 or above
FortiSIEM 6.6 6.6 all versions Migrate to a fixed release
FortiSIEM 6.5 6.5 all versions Migrate to a fixed release
FortiSIEM 6.4 6.4 all versions Migrate to a fixed release
FortiSIEM 6.3 6.3 all versions Migrate to a fixed release
FortiSIEM 6.2 6.2 all versions Migrate to a fixed release
FortiSIEM 6.1 6.1 all versions Migrate to a fixed release
FortiSIEM 5.4 5.4 all versions Migrate to a fixed release
FortiSIEM 5.3 5.3 all versions Migrate to a fixed release
FortiSIEM 5.2 5.2 all versions Migrate to a fixed release
FortiSIEM 5.1 5.1 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Théo Leleu and Austin Stark of Fortinet Product Security team.

Timeline

2023-06-12: Initial publication