CVE-2021-26098: Predictable session IDs of FSA's JSON API
An instance of small space of random values in FortiSandbox RPC API may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.
Other sources
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26098?
CVE-2021-26098 is a vulnerability in the RPC API of FortiSandbox before version 4.0.0 that allows an attacker to predict valid session IDs using a few pieces of information about the device's state.
What is the severity of CVE-2021-26098?
CVE-2021-26098 has a severity rating of 7.5 (high).
How does CVE-2021-26098 affect FortiSandbox?
CVE-2021-26098 affects FortiSandbox versions up to 3.1.4 and versions between 3.2.0 and 3.2.3.
How can an attacker exploit CVE-2021-26098?
An attacker exploiting CVE-2021-26098 can use a small space of random values to predict valid session IDs by knowing some information about the device's state.
Is there a fix for CVE-2021-26098?
The fix for CVE-2021-26098 is to upgrade to FortiSandbox version 4.0.0 or later.