Insufficient logging and lack of limitation of failed authentication attempts

Summary

An insufficient logging [CWE-778] vulnerability in FortiSandbox and FortiDeceptor may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.

Affected Products

FortiSandbox version 3.1.0 through 3.1.5
FortiSandbox version 3.2.0 through 3.2.3
FortiSandbox version 4.0.0 through 4.0.2
FortiDeceptor version 4.2.0
FortiDeceptor version 4.1.0 through 4.1.1
FortiDeceptor version 4.0.0 through 4.0.2
FortiDeceptor version 3.3.0 through 3.3.3
FortiDeceptor version 3.2.0 through 3.2.2
FortiDeceptor version 3.1.0 through 3.1.1
FortiDeceptor version 3.0.0 through 3.0.2

Solutions

Please upgrade to FortiSandbox version 4.2.1 or above
Please upgrade to FortiDeceptor version 4.3.0 or above

Acknowledgement

Fortinet is pleased to thank Mohamed Elobeid for reporting this vulnerability under responsible disclosure.

Timeline

2022-12-06: Initial publication