CVE-2025-46215
An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 al
Severity
Medium 5
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.7th percentile
Discovered by
Third party
Vendor advisory field
Published
Nov 18, 2025
Assigned by fortinet
Description
An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.
Weakness: CWE-653
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSandbox | Threat Detection & Sandbox | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSandbox
Credit
Fortinet is pleased to thank Greg Roll for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiSandbox version 5.0.2 or above Upgrade to FortiSandbox version 4.4.8 or above