Random Value Predictability in FortiSandbox RPC API by Fortinet
CVE-2021-26098
5.3MEDIUM
Summary
The RPC API of FortiSandbox versions prior to 4.0.0 contains a vulnerability that allows an attacker with limited knowledge about the device to potentially predict valid session IDs. This security issue stems from a small space of random values that can be exploited, enabling unauthorized access to sessions. It is crucial for users to implement security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Fortinet FortiSandbox FortiSandbox before 4.0.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved