Fortinet FortiSandbox是美国飞塔(Fortinet)公司的一款APT(高级持续性威胁)防护设备。该设备提供双重沙盒技术、动态威胁智能系统、实时控制面板和报告等功能。 Fortinet FortiSandbox 4.0.0 到 4.0.2、3.2.0 到 3.2.3 、 3.1.0 到 3.1.5版本存在安全漏洞,该漏洞源于日志记录不足,攻击者利用该漏洞可以重复输入不正确的凭据而无需 导致日志条目,并且对失败的身份验证尝试次数没有限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fortinet | FortiSandbox | 4.0.0 ~ 4.0.2 | - |
|
| Fortinet | FortiDeceptor | 4.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-35843 | 7.7 HIGH | Fortinet FortiOS授权问题漏洞 |
| CVE-2022-33875 | 5.1 MEDIUM | Fortinet FortiADC SQL注入漏洞 |
| CVE-2022-33876 | 5.1 MEDIUM | Fortinet FortiADC 输入验证错误漏洞 |
| CVE-2022-40680 | 3.8 LOW | Fortinet FortiOS 跨站脚本漏洞 |
| CVE-2022-38379 | 3.4 LOW | Fortinet FortiSOAR 跨站脚本漏洞 |
No comments yet