CVE-2022-26115: High severity fortinet fortisandbox firmware vulnerability
A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-26115?
CVE-2022-26115 is a vulnerability in FortiSandbox before 4.2.0 that allows an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
What is the severity of CVE-2022-26115?
The severity of CVE-2022-26115 is high.
Which software versions are affected by CVE-2022-26115?
FortiSandbox versions 3.2.0, 3.2.1, 3.2.2, 3.2.3, 4.0.0, 4.0.1, and 4.0.2 are all affected by CVE-2022-26115.
How can an attacker exploit CVE-2022-26115?
An attacker with access to the password database can exploit CVE-2022-26115 by efficiently mounting bulk guessing attacks to recover the passwords.
Where can I find more information about CVE-2022-26115?
You can find more information about CVE-2022-26115 at the FortiGuard Advisory FG-IR-20-220 on the FortiGuard website.