Latest fortinet fortisandbox Vulnerabilities

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 throug...
Fortinet FortiSandbox>=3.0.0<=3.0.7
Fortinet FortiSandbox>=3.1.0<=3.1.5
Fortinet FortiSandbox>=3.2.0<=3.2.4
Fortinet FortiSandbox>=4.0.0<=4.0.4
Fortinet FortiSandbox>=4.2.0<=4.2.5
Fortinet FortiSandbox=4.4.0
and 2 more
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 throu...
Fortinet FortiSandbox>=3.1.0<=3.1.5
Fortinet FortiSandbox>=3.2.0<=3.2.4
Fortinet FortiSandbox>=4.0.0<=4.0.4
Fortinet FortiSandbox>=4.2.0<=4.2.5
Fortinet FortiSandbox=4.4.0
Fortinet FortiSandbox=4.4.1
and 1 more
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 throug...
Fortinet FortiSandbox>=2.5.0<=2.5.2
Fortinet FortiSandbox>=3.0.0<=3.0.7
Fortinet FortiSandbox>=3.1.0<=3.1.5
Fortinet FortiSandbox>=3.2.0<=3.2.4
Fortinet FortiSandbox>=4.0.0<=4.0.3
Fortinet FortiSandbox>=4.2.0<=4.2.5
and 1 more
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 throug...
Fortinet FortiSandbox>=2.5.0<=2.5.2
Fortinet FortiSandbox>=3.0.0<=3.0.7
Fortinet FortiSandbox>=3.1.0<=3.1.5
Fortinet FortiSandbox>=3.2.0<=3.2.4
Fortinet FortiSandbox>=4.0.0<=4.0.3
Fortinet FortiSandbox>=4.2.0<=4.2.5
and 1 more
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 allows attacker ...
Fortinet FortiSandbox>=2.5.0<=2.5.2
Fortinet FortiSandbox>=3.0.0<=3.0.7
Fortinet FortiSandbox>=3.1.0<=3.1.5
Fortinet FortiSandbox>=3.2.0<=3.2.4
Fortinet FortiSandbox>=4.0.0<=4.0.3
Fortinet FortiSandbox>=4.2.0<=4.2.5
and 1 more
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.0 and 4.2.0 through 4.2.4, and 4.0.0 through 4.0.4 and 3.2.0 through 3.2.4 ...
Fortinet FortiSandbox>=3.0.4<=3.0.7
Fortinet FortiSandbox>=3.1.0<=3.1.5
Fortinet FortiSandbox>=3.2.0<=3.2.4
Fortinet FortiSandbox>=4.0.0<=4.0.4
Fortinet FortiSandbox>=4.2.0<=4.2.4
Fortinet FortiSandbox=4.4.0
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 through 3.2.4 and 2.5....
Fortinet FortiSandbox>=2.4.0<=2.4.1
Fortinet FortiSandbox>=2.5.0<=2.5.2
Fortinet FortiSandbox>=3.2.0<=3.2.4
Fortinet FortiSandbox>=4.0.0<=4.0.3
Fortinet FortiSandbox>=4.2.0<=4.2.5
Fortinet FortiSandbox=4.4.0
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x...
Fortinet FortiAnalyzer>=6.0.0<=6.0.12
Fortinet FortiAnalyzer>=6.2.9<=6.4.7
Fortinet FortiAnalyzer=7.0.0
Fortinet FortiAnalyzer=7.0.1
Fortinet FortiAnalyzer=7.0.2
Fortinet FortiManager>=6.0.0<=6.0.12
and 14 more
A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows ...
Fortinet FortiDeceptor>=1.0<3.3.3
Fortinet FortiDeceptor>=4.0.0<=4.0.2
Fortinet FortiDeceptor=4.1.0
Fortinet FortiSandbox>=2.5.0<3.2.4
Fortinet FortiSandbox>=4.0.0<4.0.3
Fortinet FortiSandbox>=4.2.0<4.2.3
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0, 4.0.0 through 4.0.2, 3.2.0 through 3.2.3, 3.1.x an...
Fortinet FortiSandbox>=3.0.1<=3.0.7
Fortinet FortiSandbox>=3.1.0<3.2.4
Fortinet FortiSandbox>=4.0.0<4.0.3
Fortinet FortiSandbox=4.2.0
A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk ...
Fortinet FortiSandbox=3.2.0
Fortinet FortiSandbox=3.2.1
Fortinet FortiSandbox=3.2.2
Fortinet FortiSandbox=3.2.3
Fortinet FortiSandbox=4.0.0
Fortinet FortiSandbox=4.0.1
and 1 more
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3...
Fortinet FortiDeceptor>=3.0.0<=3.0.2
Fortinet FortiDeceptor>=3.2.0<=3.2.2
Fortinet FortiDeceptor>=3.3.0<=3.3.3
Fortinet FortiDeceptor>=4.0.0<=4.0.2
Fortinet FortiDeceptor=3.1.0
Fortinet FortiDeceptor=3.1.1
and 9 more
An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests.
Fortinet FortiSandbox<=3.1.4
Fortinet FortiSandbox=3.2.0
Fortinet FortiSandbox=3.2.1
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0....
Fortinet FortiADC>=5.0.0<=5.4.4
Fortinet FortiADC>=6.0.0<=6.0.3
Fortinet FortiADC>=6.1.0<=6.1.3
Fortinet FortiADC=6.2.0
Fortinet FortiADC=6.2.1
Fortinet FortiMail
and 16 more
An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users conf...
Fortinet FortiSandbox<3.2.2
An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration f...
Fortinet FortiSandbox<3.1.5
Fortinet FortiSandbox>=3.2.0<3.2.2
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator be...
Fortinet FortiAuthenticator>=4.0.0<=4.3.4
Fortinet FortiAuthenticator>=5.0.0<=5.5.0
Fortinet FortiAuthenticator>=6.0.0<6.0.6
Fortinet FortiSandbox>=3.0.0<3.0.7
Fortinet FortiSandbox>=3.1.0<3.1.5
Fortinet FortiSandbox>=3.2.0<3.2.2
Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via specif...
Fortinet FortiSandbox<=3.1.4
Fortinet FortiSandbox>=3.2.0<3.2.3
Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate memory and alter its content by means of specifical...
Fortinet FortiSandbox<=3.1.4
Fortinet FortiSandbox>=3.2.0<3.2.3
Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute...
Fortinet FortiSandbox<3.1.5
Fortinet FortiSandbox>=3.2.0<3.2.2
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker...
Fortinet FortiSandbox<3.0.7
Fortinet FortiSandbox>=3.1.0<3.1.5
Fortinet FortiSandbox>=3.2.0<3.2.3
Fortinet FortiSandbox<=3.1.4
Fortinet FortiSandbox>=3.2.0<3.2.3
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's sh...
Fortinet FortiSandbox<3.2.2
A concurrent execution using shared resource with improper synchronization ('race condition') in the command shell of FortiSandbox before 3.2.2 may allow an authenticated attacker to bring the system ...
Fortinet FortiSandbox<3.2.2
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan comp...
Fortinet FortiSandbox<3.0.0

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203