Low severity3.7NVD Advisory· Published Dec 6, 2022· Updated Jun 17, 2026
CVE-2022-30305
CVE-2022-30305
Description
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.
Affected products
15cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*range: >=3.0.0,<=3.0.2
- cpe:2.3:a:fortinet:fortideceptor:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortideceptor:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortideceptor:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortideceptor:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortideceptor:4.2.0:*:*:*:*:*:*:*
- (no CPE)range: 4.2.0, 4.1.0-4.1.1, 4.0.0-4.0.2, 3.3.0-3.3.3, 3.2.0-3.2.2, 3.1.0-3.1.1, 3.0.0-3.0.2
- (no CPE)range: 4.2.0
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: >=3.1.0,<=3.1.5
- cpe:2.3:a:fortinet:fortisandbox:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortisandbox:3.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortisandbox:3.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortisandbox:3.2.3:*:*:*:*:*:*:*
- (no CPE)range: 4.0.0-4.0.2, 3.2.0-3.2.3, 3.1.0-3.1.5
- (no CPE)range: 4.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-21-170nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.