CVE-2025-46215: File scan result bypass
An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.
Other sources
An Improper Isolation or Compartmentalization vulnerability [CWE-653] in FortiSandbox may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46215?
CVE-2025-46215 is classified as a critical vulnerability due to its potential to allow unauthenticated attackers to evade sandboxing scans.
How do I fix CVE-2025-46215?
To mitigate CVE-2025-46215, update Fortinet FortiSandbox to version 5.0.2 or later, or to version 4.4.8 for versions 4.4.0 to 4.4.7.
Which Fortinet FortiSandbox versions are affected by CVE-2025-46215?
CVE-2025-46215 affects Fortinet FortiSandbox versions 5.0.0 to 5.0.1, 4.4.0 to 4.4.7, as well as all versions of 4.2 and 4.0.
What type of vulnerability is CVE-2025-46215?
CVE-2025-46215 is an Improper Isolation or Compartmentalization vulnerability, categorized under CWE-653.
Can CVE-2025-46215 be exploited remotely?
Yes, CVE-2025-46215 can be exploited by an unauthenticated remote attacker.