Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-26115


A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.


Published

2023-02-16T19:15:12.047

Last Modified

2024-11-21T06:53:27.627

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-916
  • Type: Primary
    CWE-916

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortisandbox 3.2.0 Yes
Application fortinet fortisandbox 3.2.1 Yes
Application fortinet fortisandbox 3.2.2 Yes
Application fortinet fortisandbox 3.2.3 Yes
Application fortinet fortisandbox 4.0.0 Yes
Application fortinet fortisandbox 4.0.1 Yes
Application fortinet fortisandbox 4.0.2 Yes

References