CVE-2026-59835
גבוהה 8.6
תיאור (מקור, אנגלית)
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
מדדים
- CVSS 3.1
-
8.6 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-14/8/2026
- CWE
- CWE-668
מוצרים מושפעים
fortinet: fortisandbox
קישורים
- https://fortiguard.fortinet.com/psirt/FG-IR-26-145 Vendor Advisory