imPC@ndo IT

Tracker / CVE-2021-26098

CVE-2021-26098

Medium 5.3

An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.

Affected products and versions

fortinet fortisandbox · … → 3.1.4
fortinet fortisandbox · 3.2.0 → 3.2.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References