CVE-2022-30305: High severity fortinet fortideceptor vulnerability
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-30305.
What is the severity of CVE-2022-30305?
The severity of CVE-2022-30305 is high with a CVSS base score of 7.5.
Which software versions are affected by CVE-2022-30305?
FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3, and 3.1.0 to 3.1.5; and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2, 3.1.0 through 3.1.1, and 3.0.0 through 3.0.2 are affected by this vulnerability.
What is the CWE ID of CVE-2022-30305?
The CWE ID of CVE-2022-30305 is CWE-778.
How can I fix the CVE-2022-30305 vulnerability?
To fix the CVE-2022-30305 vulnerability, it is recommended to update to the latest patched version of the affected software.