cbcvebase.
CVE-2022-27487
published 2023-04-11

CVE-2022-27487: A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0…

PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.97%
58.1th percentile
A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests.

Affected

23 ranges
VendorProductVersion rangeFixed in
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor
fortinetfortideceptor>= 1.0 < 3.3.33.3.3
fortinetfortideceptor1.0.0 – 1.0.1
fortinetfortideceptor3.0.0 – 3.0.2
fortinetfortideceptor3.1.0 – 3.1.1
fortinetfortideceptor3.2.0 – 3.2.2
fortinetfortideceptor3.3.0 – 3.3.3
fortinetfortideceptor4.0.0 – 4.0.2
fortinetfortinet
fortinetfortisandbox
fortinetfortisandbox>= 2.5.0 < 3.2.43.2.4
fortinetfortisandbox2.5.0 – 2.5.2
fortinetfortisandbox3.0.0 – 3.0.7
fortinetfortisandbox3.1.0 – 3.1.5
fortinetfortisandbox3.2.0 – 3.2.3
fortinetfortisandbox>= 4.0.0 < 4.0.34.0.3
fortinetfortisandbox4.0.0 – 4.0.2
fortinetfortisandbox>= 4.2.0 < 4.2.34.2.3
fortinetfortisandbox4.2.0 – 4.2.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.