Vulnerability Description
A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortisandbox | 3.2.0 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-20-220Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-20-220Vendor Advisory
FAQ
What is CVE-2022-26115?
CVE-2022-26115 is a vulnerability with a CVSS score of 5.9 (MEDIUM). A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk ...
How severe is CVE-2022-26115?
CVE-2022-26115 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26115?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortisandbox.