FG-IR-20-218: Predictable session IDs of FSA's JSON API
An instance of small space of random values in FortiSandbox RPC API may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-20-218?
The severity of FG-IR-20-218 is classified as medium due to the potential for session ID prediction.
How do I fix FG-IR-20-218?
To fix FG-IR-20-218, ensure that your FortiSandbox system is updated to the latest firmware version that addresses this vulnerability.
What are the potential consequences of FG-IR-20-218?
The potential consequences of FG-IR-20-218 include unauthorized access to sessions if session IDs are successfully predicted.
Who is affected by FG-IR-20-218?
FG-IR-20-218 affects users of Fortinet FortiSandbox running vulnerable versions of its firmware.
Is FG-IR-20-218 being actively exploited?
There is no public indication that FG-IR-20-218 is being actively exploited, but it is advisable to mitigate the risk by applying updates.