CVE-2022-30305

LOW

FortiDeceptor & FortiSandbox - Insufficient Logging of Failed Authentication Attempts

Title source: llm
STIX 2.1

Description

An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.

References (1)

Core 1
Core References

Scores

CVSS v3 3.7
EPSS 0.0022
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-778 CWE-307
Status published
Products (11)
fortinet/fortideceptor 3.1.0
fortinet/fortideceptor 3.1.1
fortinet/fortideceptor 4.1.0
fortinet/fortideceptor 4.1.1
fortinet/fortideceptor 4.2.0
fortinet/fortideceptor 3.0.0 - 3.0.2
fortinet/fortisandbox 3.2.0
fortinet/fortisandbox 3.2.1
fortinet/fortisandbox 3.2.2
fortinet/fortisandbox 3.2.3
... and 1 more
Published Dec 06, 2022
Tracked Since Feb 18, 2026