CVE-2022-30305
published 2022-12-06CVE-2022-30305: An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.61%
45.2th percentile
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | — | — |
| fortinet | fortideceptor | 3.0.0 – 3.0.2 | — |
| fortinet | fortideceptor | 3.1.0 – 3.1.1 | — |
| fortinet | fortideceptor | 3.2.0 – 3.2.2 | — |
| fortinet | fortideceptor | 3.3.0 – 3.3.3 | — |
| fortinet | fortideceptor | 4.0.0 – 4.0.2 | — |
| fortinet | fortideceptor | 4.1.0 – 4.1.1 | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | 3.1.0 – 3.1.5 | — |
| fortinet | fortisandbox | 3.2.0 – 3.2.3 | — |
| fortinet | fortisandbox | 4.0.0 – 4.0.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1...
vendor_fortinet·2022-12-06·CVSS 3.7
CVE-2022-30305 [LOW] CWE-307 An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1...
FG-IR-21-170: An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1...
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.
CVEs: CVE-2022-30305
CWEs: CWE-307, CWE-778
CVSS: 3.7 (low)
Affected products: FortiDeceptor, FortiSandbox
GHSA
GHSA-486j-wqfq-g6vq: An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4
ghsa_unreviewed·2022-12-06
CVE-2022-30305 [HIGH] GHSA-486j-wqfq-g6vq: An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-06
Published