Description
A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to FortiSandbox version 4.2.0 and above.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-30682 | A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-20-220 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:49:13.825Z
Reserved: 2022-02-25T14:18:24.278Z
Link: CVE-2022-26115
Updated: 2024-08-03T04:56:37.500Z
Status : Modified
Published: 2023-02-16T19:15:12.047
Modified: 2024-11-21T06:53:27.627
Link: CVE-2022-26115
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD