Use of hardcoded key used for remote backup server password encryption

Summary

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.

Version Affected Solution
FortiSandbox 5.0 5.0.0 Upgrade to 5.0.1 or above
FortiSandbox 4.4 4.4.0 through 4.4.6 Upgrade to 4.4.7 or above
FortiSandbox 4.2 4.2.1 through 4.2.7 Upgrade to 4.2.8 or above
FortiSandbox 4.0 4.0.0 through 4.0.5 Upgrade to 4.0.6 or above
FortiSandbox 3.2 3.2 all versions Migrate to a fixed release
FortiSandbox 3.1 3.1 all versions Migrate to a fixed release
FortiSandbox 3.0 3.0.5 through 3.0.7 Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2025-03-11: Initial publication