Insufficient Session Expiration in FortiSandbox by Fortinet
CVE-2020-29012
5.6MEDIUM
What is CVE-2020-29012?
FortiSandbox versions 3.2.1 and earlier have an insufficient session expiration vulnerability. This flaw enables attackers to exploit unexpired administrative user session IDs, potentially allowing unauthorized access to information about other users configured on the device. If attackers can obtain a valid session ID through hypothetical methods, they may compromise other user sessions, posing a significant security risk.
Affected Version(s)
Fortinet FortiSandbox FortiSandbox 3.2.1,