A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
2023-02-16T19:15:12.047
2024-11-21T06:53:27.627
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortisandbox | 3.2.0 | Yes |
Application | fortinet | fortisandbox | 3.2.1 | Yes |
Application | fortinet | fortisandbox | 3.2.2 | Yes |
Application | fortinet | fortisandbox | 3.2.3 | Yes |
Application | fortinet | fortisandbox | 4.0.0 | Yes |
Application | fortinet | fortisandbox | 4.0.1 | Yes |
Application | fortinet | fortisandbox | 4.0.2 | Yes |