FortiSandbox VNC exposure: what to know
A vulnerability in FortiSandbox could allow unauthenticated attackers to reach the VNC server of certain scanning VMs. FortiSandboxPaaS is not affected, and some models are impacted.
A vulnerability in FortiSandbox could allow unauthenticated attackers to reach the VNC server of certain scanning VMs. FortiSandboxPaaS is not affected, and some models are impacted.
FortiSIEM is affected by a Basic XSS vulnerability related to improper neutralization of script-related HTML tags. In certain cases, a privileged administrator could execute unauthorized commands.
FortiGuard Labs disclosed a FortiOS buffer over-read issue affecting FortiOS, FortiProxy, and FortiSASE. Authenticated attackers may obtain a portion of device memory via a crafted redirect request.