Insufficient logging and lack of limitation of failed authentication attempts


An insufficient logging [CWE-778] vulnerability in FortiSandbox and FortiDeceptor may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.

Affected Products

FortiSandbox version 3.1.0 through 3.1.5
FortiSandbox version 3.2.0 through 3.2.3
FortiSandbox version 4.0.0 through 4.0.2

FortiDeceptor version 4.2.0
FortiDeceptor version 4.1.0 through 4.1.1
FortiDeceptor version 4.0.0 through 4.0.2
FortiDeceptor version 3.3.0 through 3.3.3
FortiDeceptor version 3.2.0 through 3.2.2
FortiDeceptor version 3.1.0 through 3.1.1
FortiDeceptor version 3.0.0 through 3.0.2


Please upgrade to FortiSandbox version 4.2.1 or above

Please upgrade to FortiDeceptor version 4.3.0 or above


Fortinet is pleased to thank Mohamed Elobeid for reporting this vulnerability under responsible disclosure.