7.5
CVE-2022-26115
- EPSS 0.1%
- Published 16.02.2023 19:15:12
- Last modified 21.11.2024 06:53:27
- Source psirt@fortinet.com
- Teams watchlist Login
- Open Login
A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
Data is provided by the National Vulnerability Database (NVD)
Fortinet ≫ Fortisandbox Version3.2.0
Fortinet ≫ Fortisandbox Version3.2.1
Fortinet ≫ Fortisandbox Version3.2.2
Fortinet ≫ Fortisandbox Version3.2.3
Fortinet ≫ Fortisandbox Version4.0.0
Fortinet ≫ Fortisandbox Version4.0.1
Fortinet ≫ Fortisandbox Version4.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.242 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
psirt@fortinet.com | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-916 Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.