CVE-2022-30305
Estado: ModificadaAlta (7.5)—
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.63%
- Percentil entre todas las CVEs puntuadas: 48
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-778
- CWE-307, NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-30305",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-30305",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-10-22T20:18:52.650973Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@fortinet.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@fortinet.com",
"affectedData": [
{
"vendor": "Fortinet",
"product": "FortiSandbox",
"versions": [
{
"status": "affected",
"version": "4.0.0",
"versionType": "semver",
"lessThanOrEqual": "4.0.2"
},
{
"status": "affected",
"version": "3.2.0",
"versionType": "semver",
"lessThanOrEqual": "3.2.3"
},
{
"status": "affected",
"version": "3.1.0",
"versionType": "semver",
"lessThanOrEqual": "3.1.5"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Fortinet",
"product": "FortiDeceptor",
"versions": [
{
"status": "affected",
"version": "4.2.0"
},
{
"status": "affected",
"version": "4.1.0",
"versionType": "semver",
"lessThanOrEqual": "4.1.1"
},
{
"status": "affected",
"version": "4.0.0",
"versionType": "semver",
"lessThanOrEqual": "4.0.2"
},
{
"status": "affected",
"version": "3.3.0",
"versionType": "semver",
"lessThanOrEqual": "3.3.3"
},
{
"status": "affected",
"version": "3.2.0",
"versionType": "semver",
"lessThanOrEqual": "3.2.2"
},
{
"status": "affected",
"version": "3.1.0",
"versionType": "semver",
"lessThanOrEqual": "3.1.1"
},
{
"status": "affected",
"version": "3.0.0",
"versionType": "semver",
"lessThanOrEqual": "3.0.2"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2022-12-06T17:15:10.660",
"references": [
{
"url": "https://fortiguard.com/psirt/FG-IR-21-170",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@fortinet.com"
},
{
"url": "https://fortiguard.com/psirt/FG-IR-21-170",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@fortinet.com",
"description": [
{
"lang": "en",
"value": "CWE-778"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-307"
},
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials without causing a log entry, and with no limit on the number of failed authentication attempts."
},
{
"lang": "es",
"value": "Una vulnerabilidad de registro insuficiente [CWE-778] en las versiones 4.0.0 a 4.0.2, 3.2.0 a 3.2.3 y 3.1.0 a 3.1.5 de FortiSandbox y las versiones 4.2.0, 4.1.0 a 4.1.1 de FortiDeceptor. 4.0.0 a 4.0.2, 3.3.0 a 3.3.3, 3.2.0 a 3.2.2, 3.1.0 a 3.1.1 y 3.0.0 a 3.0.2 pueden permitir que un atacante remoto ingrese repetidamente credenciales incorrectas sin generar una entrada de registro y sin límite en el número de intentos fallidos de autenticación."
}
],
"lastModified": "2026-06-17T04:43:27.270",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01A6C490-83C0-439C-BC36-157D732F362B",
"versionEndIncluding": "3.0.2",
"versionStartIncluding": "3.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD1D0126-C1C4-4F76-A78F-F0BEC7B3EB0C",
"versionEndIncluding": "3.2.2",
"versionStartIncluding": "3.2.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "840D39F9-C790-4AF6-9E9D-2299083C008A",
"versionEndIncluding": "3.3.3",
"versionStartIncluding": "3.3.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortideceptor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16BF9690-3D39-4FCC-A314-68C17E1E0892",
"versionEndIncluding": "4.0.2",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortideceptor:3.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67A22BDE-857F-4A92-A027-38C4A6D6144D"
},
{
"criteria": "cpe:2.3:a:fortinet:fortideceptor:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DB5762A-D14A-4F7F-A9DA-1979FFFBF1E1"
},
{
"criteria": "cpe:2.3:a:fortinet:fortideceptor:4.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48655ECC-C9A9-4AD9-993B-7B2965E9266F"
},
{
"criteria": "cpe:2.3:a:fortinet:fortideceptor:4.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2CF71B3-7E56-4D31-BE5D-682D553249BB"
},
{
"criteria": "cpe:2.3:a:fortinet:fortideceptor:4.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC3F4599-8FB1-40AF-96A9-11B58DE44C95"
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C47A3DB-A02A-488D-B0E1-867A19CE43B8",
"versionEndIncluding": "3.1.5",
"versionStartIncluding": "3.1.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30CE4EF6-1AC0-49A2-BC7B-43D1B453DC3B",
"versionEndIncluding": "4.0.2",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:3.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3DDB3490-E30F-45CC-81B7-EFB5C1A60DA7"
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:3.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "143DD85B-4CE7-409D-B215-6069D2EF33D0"
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:3.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53070F6A-CC5B-43C9-96F9-2C0930A8D3CE"
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:3.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B38F72A-A271-43FE-8FBF-02AB87BA9D47"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@fortinet.com"
}