CVE-2021-26098
published 2021-08-04CVE-2021-26098: An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.81%
52.9th percentile
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet_fortisandbox | — | — |
| fortinet | fortisandbox | <= 3.1.4 | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | >= 3.2.0 < 3.2.3 | 3.2.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possess...
vendor_fortinet·2021-08-04·CVSS 5.3
CVE-2021-26098 [MEDIUM] CWE-330 An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possess...
FG-IR-20-218: An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possess...
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.
CVEs: CVE-2021-26098
CWEs: CWE-330
CVSS: 5.3 (medium)
Affected products: FortiSandbox
GHSA
GHSA-6g87-jg5m-ppfq: An instance of small space of random values in the RPC API of FortiSandbox before 4
ghsa_unreviewed·2022-05-24
CVE-2021-26098 [HIGH] CWE-330 GHSA-6g87-jg5m-ppfq: An instance of small space of random values in the RPC API of FortiSandbox before 4
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-04
Published