Improper password storage mechanism

Summary

A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.

Affected Products

FortiDeceptor 24 all versions are not affected
FortiDeceptor 6.0 all versions are not affected
FortiDeceptor 5.3 all versions are not affected
FortiDeceptor 5.2 all versions are not affected
FortiDeceptor 5.1 all versions are not affected
FortiDeceptor version 5.0.0
FortiDeceptor 4.3 all versions
FortiDeceptor 4.2 all versions
FortiDeceptor 4.1 all versions
FortiDeceptor 4.0 all versions
FortiDeceptor 3.3 all versions
FortiDeceptor 3.2 all versions
FortiDeceptor 3.1 all versions
FortiDeceptor 3.0 all versions
FortiSandbox 5.0 all versions are not affected
FortiSandbox 4.4 all versions are not affected
FortiSandbox 4.2 all versions are not affected
FortiSandbox 4.0 all versions
FortiSandbox 3.2 all versions

Solutions

Upgrade to FortiSandbox version 4.2.0 and above.

Acknowledgement

Internally discovered by Giuseppe Cocomazzi.

Timeline

2023-02-16: Initial publication