imPC@ndo EN

Tracker / CVE-2022-30305

CVE-2022-30305

Bassa 3.7

An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.

Prodotti e versioni affette

fortinet fortideceptor
fortinet fortideceptor · 3.0.0 → 3.0.2
fortinet fortideceptor · 3.2.0 → 3.2.2
fortinet fortideceptor · 3.3.0 → 3.3.3
fortinet fortideceptor · 4.0.0 → 4.0.2
fortinet fortisandbox
fortinet fortisandbox · 3.1.0 → 3.1.5
fortinet fortisandbox · 4.0.0 → 4.0.2

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti