FortiSandbox & FortiDeceptor - Insufficient logging and lack of limitation of failed authentication attempts
Summary
An insufficient logging [CWE-778] vulnerability in FortiSandbox and FortiDeceptor may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.
Affected Products
FortiSandbox version 3.1.0 through 3.1.5
FortiSandbox version 3.2.0 through 3.2.3
FortiSandbox version 4.0.0 through 4.0.2
FortiDeceptor version 4.2.0
FortiDeceptor version 4.1.0 through 4.1.1
FortiDeceptor version 4.0.0 through 4.0.2
FortiDeceptor version 3.3.0 through 3.3.3
FortiDeceptor version 3.2.0 through 3.2.2
FortiDeceptor version 3.1.0 through 3.1.1
FortiDeceptor version 3.0.0 through 3.0.2
Solutions
Please upgrade to FortiSandbox version 4.2.1 or above
Please upgrade to FortiDeceptor version 4.3.0 or above