7.5
CVE-2022-26115
- EPSS 0.32%
- Veröffentlicht 16.02.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 06:53:27
- Erkennungen
A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortisandbox Version 3.2.0
Fortinet ≫ Fortisandbox Version 3.2.1
Fortinet ≫ Fortisandbox Version 3.2.2
Fortinet ≫ Fortisandbox Version 3.2.3
Fortinet ≫ Fortisandbox Version 4.0.0
Fortinet ≫ Fortisandbox Version 4.0.1
Fortinet ≫ Fortisandbox Version 4.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.23 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| Fortinet | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-916 Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
https://fortiguard.com/psirt/FG-IR-20-220