CVE-2020-29013Improper Input Validation in Fortinet Fortisandbox

Severity
5.4MEDIUMNVD
EPSS
0.4%
top 39.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 6
Latest updateApr 7

Description

An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

CVEListV5fortinet/fortinet_fortisandboxFortiSandbox before 3.2.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-85hj-p83w-mp25: An improper input validation vulnerability in the sniffer interface of FortiSandbox before 32022-04-07
CVEList
CVE-2020-29013: An improper input validation vulnerability in the sniffer interface of FortiSandbox before 32022-04-06

📋Vendor Advisories

1
Fortinet
An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authentica...2022-04-06
CVE-2020-29013 — Improper Input Validation in Fortinet | cvebase