A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortisandbox | 3.2.2 | 3.2.2.x |
| fortinet / fortisandbox | 4.0.0 | 4.0.0.x |
| fortinet / fortisandbox | 3.2.0 | 3.2.0.x |
| fortinet / fortisandbox | 3.2.1 | 3.2.1.x |
| fortinet / fortisandbox | 3.2.3 | 3.2.3.x |
| fortinet / fortisandbox | 4.0.1 | 4.0.1.x |
| fortinet / fortisandbox | 4.0.2 | 4.0.2.x |