CVE-2021-26098

Publication date

2021-08-04 13:20:48

Family

fortinet

State

PUBLISHED

Description

An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.