FG-IR-20-071: Unauthorized user able to download the device configuration file
An improper access control vulnerability (CWE-284) in FortiSandbox may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-20-071?
The severity of FG-IR-20-071 is classified as high due to the improper access control vulnerability allowing unprivileged attackers to download sensitive configuration files.
How do I fix FG-IR-20-071?
To fix FG-IR-20-071, ensure that the device is updated to the latest FortiSandbox firmware version that addresses this vulnerability.
What types of attackers can exploit FG-IR-20-071?
Authenticated, unprivileged attackers can exploit FG-IR-20-071 to gain access to restricted configuration files.
What are the consequences of not addressing FG-IR-20-071?
Failing to address FG-IR-20-071 could lead to unauthorized access to sensitive device configurations, compromising the security of the affected system.
Is FG-IR-20-071 specific to any Fortinet products?
Yes, FG-IR-20-071 specifically affects the Fortinet FortiSandbox product.