CVE-2020-29013: Insufficient validation logic in Fortisandbox sniffer's max file size
An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests.
Other sources
An improper input validation vulnerability in the sniffer interface of FortiSandbox may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests.
— FortiGuard
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-29013?
CVE-2020-29013 is an improper input validation vulnerability in the sniffer interface of FortiSandbox before version 3.2.2.
How does CVE-2020-29013 affect FortiSandbox?
CVE-2020-29013 may allow an authenticated attacker to silently halt the sniffer of FortiSandbox via specifically crafted requests.
What is the severity of CVE-2020-29013?
CVE-2020-29013 has a severity rating of medium with a CVSS score of 5.4.
Which versions of FortiSandbox are affected by CVE-2020-29013?
FortiSandbox versions 3.1.4, 3.2.0, and 3.2.1 are affected by CVE-2020-29013.
How can I fix CVE-2020-29013?
To fix CVE-2020-29013, upgrade FortiSandbox to version 3.2.2 or later.