Fortinet FortiAuthenticator 6.4.3

CPE Details

Fortinet FortiAuthenticator 6.4.3
6.4.3
2023-03-13
17h03 +00:00
2023-03-21
16h55 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fortinet:fortiauthenticator:6.4.3:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortiauthenticator

Version

6.4.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-23664 2024-06-03 09h50 +00:00 A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.
6.1
Medium
CVE-2022-35850 2023-04-11 16h07 +00:00 An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password" page.
6.1
Medium
CVE-2023-26208 2023-03-09 14h55 +00:00 A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
5.3
Medium