- Description
- A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
- Products
- fortisandbox
CVSS 3.1
- Type
- Secondary
- Base score
- 8.6
- Impact score
- 4.7
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- Severity
- HIGH
- psirt@fortinet.com
- CWE-668
- Hype score
- Not currently trending
⚠️ Vulnerabilidades en productos Fortinet ❗ CVE-2026-59835 ❗ CVE-2025-53379 ➡️ Más info: https://t.co/HLo07WeKka https://t.co/fR25yqHlwE
@CERTpy
27 Jul 2026
180 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
今日のパッチチューズデー(MS一旦割愛) ◆Ivanti(クリティカルなし) CVE-2026-14903 Xtractionのパストラバーサルで任意ファイル読取 https://t.co/CHHFBmlugR… ◆Fortinet(クリティカルなし) CVE-2025-53379 FortiAuthentica
@taku888infinity
14 Jul 2026
1140 Impressions
0 Retweets
4 Likes
2 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "733F4C04-3FDF-4F9D-AE7B-154FB95A5E20",
"versionEndExcluding": "4.4.9",
"versionStartIncluding": "4.4.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7A1CEA31-8309-4B13-8A3C-4830394A728D",
"versionEndExcluding": "5.0.3",
"versionStartIncluding": "5.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]