VYPR
Low severity3.7NVD Advisory· Published Mar 9, 2023· Updated Jun 17, 2026

CVE-2022-29056

CVE-2022-29056

Description

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

Affected products

4
  • cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*range: >=6.0.0,<6.0.10
    • cpe:2.3:a:fortinet:fortimail:6.4.0:*:*:*:*:*:*:*
    • (no CPE)range: 6.4.0, 6.2.0 through 6.2.4, and before 6.0.9
    • (no CPE)range: 6.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.