Authentication rate-limit bypass permits to brute force admin logins

0
6

CVSSv3 Score: 7.3

An Improper Control of Interaction Frequency vulnerability [CWE-799] in FortiWeb may allow a remote unauthenticated attacker to bypass the authentication rate-limit via crafted requests. The success of the attack depends on the attacker’s resources and the password target complexity.

Revised on 2026-03-10 00:00:00

– Read more