<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Improper password storage mechanism</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-20-220</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-02-16T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-02-16T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-02-16T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiSandbox 4.2 all versions are not affectedFortiSandbox 4.0 all versionsFortiSandbox 3.2 all versionsFortiSandbox 3.1 all versions are not affectedFortiDeceptor 5.1 all versions are not affectedFortiDeceptor version 5.0.0FortiDeceptor 4.3 all versionsFortiDeceptor 4.2 all versionsFortiDeceptor 4.1 all versionsFortiDeceptor 4.0 all versionsFortiDeceptor 3.3 all versionsFortiDeceptor 3.2 all versionsFortiDeceptor 3.1 all versionsFortiDeceptor 3.0 all versionsFortiDeceptor 2.1 all versions are not affectedFortiDeceptor 2.0 all versions are not affectedFortiDeceptor 1.1 all versions are not affectedFortiDeceptor 1.0 all versions are not affected
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Upgrade to FortiSandbox version 4.2.0 and above.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered by Giuseppe Cocomazzi.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiDeceptor" Type="Product Name">
                <Branch Name="5.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-5.0.0">FortiDeceptor 5.0.0</FullProductName>
                </Branch>
                <Branch Name="4.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-4.3.0">FortiDeceptor 4.3.0</FullProductName>
                </Branch>
                <Branch Name="4.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-4.2.0">FortiDeceptor 4.2.0</FullProductName>
                </Branch>
                <Branch Name="4.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-4.1.1">FortiDeceptor 4.1.1</FullProductName>
                </Branch>
                <Branch Name="4.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-4.1.0">FortiDeceptor 4.1.0</FullProductName>
                </Branch>
                <Branch Name="4.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-4.0.2">FortiDeceptor 4.0.2</FullProductName>
                </Branch>
                <Branch Name="4.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-4.0.1">FortiDeceptor 4.0.1</FullProductName>
                </Branch>
                <Branch Name="4.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-4.0.0">FortiDeceptor 4.0.0</FullProductName>
                </Branch>
                <Branch Name="3.3.3" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.3.3">FortiDeceptor 3.3.3</FullProductName>
                </Branch>
                <Branch Name="3.3.2" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.3.2">FortiDeceptor 3.3.2</FullProductName>
                </Branch>
                <Branch Name="3.3.1" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.3.1">FortiDeceptor 3.3.1</FullProductName>
                </Branch>
                <Branch Name="3.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.3.0">FortiDeceptor 3.3.0</FullProductName>
                </Branch>
                <Branch Name="3.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.2.2">FortiDeceptor 3.2.2</FullProductName>
                </Branch>
                <Branch Name="3.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.2.1">FortiDeceptor 3.2.1</FullProductName>
                </Branch>
                <Branch Name="3.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.2.0">FortiDeceptor 3.2.0</FullProductName>
                </Branch>
                <Branch Name="3.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.1.1">FortiDeceptor 3.1.1</FullProductName>
                </Branch>
                <Branch Name="3.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.1.0">FortiDeceptor 3.1.0</FullProductName>
                </Branch>
                <Branch Name="3.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.0.2">FortiDeceptor 3.0.2</FullProductName>
                </Branch>
                <Branch Name="3.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.0.1">FortiDeceptor 3.0.1</FullProductName>
                </Branch>
                <Branch Name="3.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiDeceptor-3.0.0">FortiDeceptor 3.0.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiSandbox" Type="Product Name">
                <Branch Name="4.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-4.0.6">FortiSandbox 4.0.6</FullProductName>
                </Branch>
                <Branch Name="4.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-4.0.5">FortiSandbox 4.0.5</FullProductName>
                </Branch>
                <Branch Name="4.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-4.0.4">FortiSandbox 4.0.4</FullProductName>
                </Branch>
                <Branch Name="4.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-4.0.3">FortiSandbox 4.0.3</FullProductName>
                </Branch>
                <Branch Name="4.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-4.0.2">FortiSandbox 4.0.2</FullProductName>
                </Branch>
                <Branch Name="4.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-4.0.1">FortiSandbox 4.0.1</FullProductName>
                </Branch>
                <Branch Name="4.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-4.0.0">FortiSandbox 4.0.0</FullProductName>
                </Branch>
                <Branch Name="3.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-3.2.4">FortiSandbox 3.2.4</FullProductName>
                </Branch>
                <Branch Name="3.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-3.2.3">FortiSandbox 3.2.3</FullProductName>
                </Branch>
                <Branch Name="3.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-3.2.2">FortiSandbox 3.2.2</FullProductName>
                </Branch>
                <Branch Name="3.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-3.2.1">FortiSandbox 3.2.1</FullProductName>
                </Branch>
                <Branch Name="3.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiSandbox-3.2.0">FortiSandbox 3.2.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Improper password storage mechanism</Title>
        <cvrf:CVE>CVE-2022-26115</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiDeceptor-5.0.0</ProductID>
                <ProductID>FortiDeceptor-4.3.0</ProductID>
                <ProductID>FortiDeceptor-4.2.0</ProductID>
                <ProductID>FortiDeceptor-4.1.1</ProductID>
                <ProductID>FortiDeceptor-4.1.0</ProductID>
                <ProductID>FortiDeceptor-4.0.2</ProductID>
                <ProductID>FortiDeceptor-4.0.1</ProductID>
                <ProductID>FortiDeceptor-4.0.0</ProductID>
                <ProductID>FortiDeceptor-3.3.3</ProductID>
                <ProductID>FortiDeceptor-3.3.2</ProductID>
                <ProductID>FortiDeceptor-3.3.1</ProductID>
                <ProductID>FortiDeceptor-3.3.0</ProductID>
                <ProductID>FortiDeceptor-3.2.2</ProductID>
                <ProductID>FortiDeceptor-3.2.1</ProductID>
                <ProductID>FortiDeceptor-3.2.0</ProductID>
                <ProductID>FortiDeceptor-3.1.1</ProductID>
                <ProductID>FortiDeceptor-3.1.0</ProductID>
                <ProductID>FortiDeceptor-3.0.2</ProductID>
                <ProductID>FortiDeceptor-3.0.1</ProductID>
                <ProductID>FortiDeceptor-3.0.0</ProductID>
                <ProductID>FortiSandbox-4.0.6</ProductID>
                <ProductID>FortiSandbox-4.0.5</ProductID>
                <ProductID>FortiSandbox-4.0.4</ProductID>
                <ProductID>FortiSandbox-4.0.3</ProductID>
                <ProductID>FortiSandbox-4.0.2</ProductID>
                <ProductID>FortiSandbox-4.0.1</ProductID>
                <ProductID>FortiSandbox-4.0.0</ProductID>
                <ProductID>FortiSandbox-3.2.4</ProductID>
                <ProductID>FortiSandbox-3.2.3</ProductID>
                <ProductID>FortiSandbox-3.2.2</ProductID>
                <ProductID>FortiSandbox-3.2.1</ProductID>
                <ProductID>FortiSandbox-3.2.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>5.4</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-20-220</URL>
                <Description>Improper password storage mechanism</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>