Impact
Fortinet FortiSandbox versions 4.4.3 through 4.4.8 and 5.0.0 through 5.0.2 contain a misconfiguration that exposes the VNC service of sandbox virtual machines to unauthenticated network requests. This flaw allows an attacker to connect to the VNC session and view or control the sandbox VM, providing access to the internal sandbox environment without needing credentials. The vulnerability is an instance of CWE‑668, improper access control of resources.
Affected Systems
Affected vendor: Fortinet. Product: FortiSandbox. Affected versions: 4.4.3‑4.4.8 and 5.0.0‑5.0.2.
Risk and Exploitability
The CVSS score is 7.7, indicating high severity, while the EPSS score is under 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation is unlikely to be widespread at present. An attacker can exploit the flaw from any network‑connected system by sending unauthenticated requests to the exposed VNC port, and the attack can be performed over the network with no authentication required.
OpenCVE Enrichment