CVE-2020-29012

MEDIUM

FortiSandbox < 3.2.2 - Insufficient Session Expiration

Title source: llm
STIX 2.1

Description

An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users configured on the device, should the attacker be able to obtain that session ID (via other, hypothetical attacks)

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-20-070

Scores

CVSS v3 5.6
EPSS 0.0020
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (1)
fortinet/fortisandbox < 3.2.2
Published Sep 08, 2021
Tracked Since Feb 18, 2026