A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortisiem | 6.4.1 | 6.4.1.x |
| fortinet / fortisiem | 6.4.0 | 6.4.0.x |
| fortinet / fortisiem | 6.3.0 | 6.3.3.x |
| fortinet / fortisiem | 6.2.1 | 6.2.1.x |
| fortinet / fortisiem | 6.2.0 | 6.2.0.x |
| fortinet / fortisiem | 5.4.0 | 5.4.0.x |
| fortinet / fortisiem | 5.3.0 | 5.3.3.x |
| fortinet / fortisiem | 6.7.0 | 6.7.0.x |
| fortinet / fortisiem | 6.5.0 | 6.5.0.x |
| fortinet / fortisiem | 6.5.1 | 6.5.1.x |
| fortinet / fortisiem | 6.4.2 | 6.4.2.x |
| fortinet / fortisiem | 6.1.0 | 6.1.0.x |
| fortinet / fortisiem | 6.1.1 | 6.1.1.x |
| fortinet / fortisiem | 6.1.2 | 6.1.2.x |
| fortinet / fortisiem | 6.7.1 | 6.7.1.x |
| fortinet / fortisiem | 6.6.0 | 6.6.3.x |