Skip to content
Beveiligingsnieuws

FortiSandbox VNC exposure: what to know

FortiSandbox VNC-toegang

The FortiGuard PSIRT advisory FG-IR-26-145 describes a security issue that relates to FortiSandbox VNC exposure. In short: under specific conditions, an attacker without authentication may be able to access the VNC service running on virtual machines used for scanning.

This matters because VNC is commonly used for remote desktop-style access. If exposed to the wrong audience, it can become a serious entry point. Below, we break down what the advisory says, which environments are affected, and what actions are (and are not) required.

What is the FortiSandbox VNC exposure issue?

The advisory reports an Exposure of Resource to Wrong Sphere vulnerability, categorized as CWE-668. This type of weakness typically means a component becomes accessible from an unintended context or trust boundary.

According to the PSIRT summary, the issue could allow an unauthenticated attacker to access the VNC server of VMs that perform scanning, via network requests.

In practical terms, this points to a scenario where the VNC service on relevant scanning virtual machines is reachable from network paths where it should not be accessible without proper authorization.

Who could be affected?

The advisory is specific about impact. It states that FortiSandboxPaaS is not impacted by this issue. As a result, customers using FortiSandboxPaaS are told they do not need to take action related to this advisory.

However, some FortiSandbox appliance models are listed as impacted. The following models are explicitly named:

  • FSA-500G
  • FSA-1500G

If you operate one of these impacted models and your deployment exposes scanning VMs over the network, you should review your network access paths and confirm whether the relevant VNC service is reachable from unintended sources.

What does “unauthenticated” mean here?

In the PSIRT description, the attacker is unauthenticated, meaning they do not need valid credentials to attempt access to the targeted VNC service. Instead, the potential access is described as being achievable through network requests.

This is a key risk distinction. Many defenses rely on authentication barriers; if those barriers do not properly protect the service boundary, the service may be reachable even when typical access controls are not invoked.

Why the advisory mentions “all interfaces”

The title of the advisory—“Unauthenticated VNC access exposed on all interfaces”—signals that the exposure concern is not limited to a single network segment or interface. The advisory wording implies that, in the affected setups, the VNC access path could be reachable across the interfaces involved in the deployment.

From a customer perspective, this increases the importance of validating firewall rules, routing, and segmentation around the scanning components—especially where management services or remote-access services like VNC could be indirectly exposed.

Is FortiSandboxPaaS impacted?

No. The advisory clearly states that FortiSandboxPaaS is not impacted. That means organizations using the PaaS offering should not be affected by this specific VNC exposure issue and, according to the PSIRT summary, do not need to perform any action based on this announcement.

What should customers do?

The PSIRT summary provides a targeted message: customers of FortiSandboxPaaS do not need to take action. For the impacted appliance models (FSA-500G and FSA-1500G), the advisory indicates an exposure risk that could allow unauthenticated access to VNC on scanning VMs.

While the advisory excerpt we reviewed does not list specific remediation steps, practical next actions typically focus on reducing exposure. For example, you can:

  • Confirm network reachability: verify whether VNC is accessible from networks that should not have direct access.
  • Review segmentation: ensure scanning VMs are isolated so only intended systems can reach them.
  • Restrict access paths: tighten firewall or security group rules so VNC-related ports are not reachable from untrusted sources.

Because the issue is described as reachable via network requests, limiting inbound access is an important protective measure. At the same time, you should follow Fortinet’s guidance in the full advisory for any version-specific fixes or recommended mitigations that may not be included in the short summary.

How to assess your exposure risk

Even if you run an impacted model, the likelihood of harm depends on your environment. Consider the following questions to gauge your risk level:

  • Are scanning VMs reachable from external networks? If not, the practical impact may be reduced, though you should still verify internal reachability.
  • Do you have strict firewall rules around management and remote-access services? If remote services are broadly reachable, risk increases.
  • Are all interfaces truly accessible from the same trust level? If your deployment spans multiple interfaces with varying trust zones, confirm that untrusted zones cannot reach VNC.

These checks help you understand whether an attacker could plausibly reach the VNC server described in the advisory.

Key takeaway from PSIRT FG-IR-26-145

The core message of FortiSandbox VNC exposure is straightforward: a vulnerability in FortiSandbox may allow an unauthenticated attacker to access the VNC server of scanning VMs through network requests.

At the same time, the PSIRT summary also offers reassurance for one major group: FortiSandboxPaaS is not impacted, and customers using that offering are not expected to take action based on this specific issue.

For deployments that include FSA-500G or FSA-1500G, it’s worth validating that VNC services are not exposed beyond the intended access boundaries.

Conclusion

FortiSandbox VNC exposure described in PSIRT advisory FG-IR-26-145 highlights a potential path to unauthenticated access to VNC on certain scanning virtual machines. The risk is relevant for the named impacted appliance models, while FortiSandboxPaaS remains unaffected.

If you use one of the impacted FortiSandbox models, prioritize verifying network access controls and segmentation around scanning components and VNC services. Following the full PSIRT guidance and confirming your exposure surface can help you reduce the chance of exploitation.

Source: https://fortiguard.fortinet.com/psirt/FG-IR-26-145