CVE-2025-46215

An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 al

Severity
Medium 5
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.7th percentile
Discovered by
Third party
Vendor advisory field
Published
Nov 18, 2025
Assigned by fortinet

Description

An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.

Weakness: CWE-653

Affected products

Vendor Product Category Matched by
Fortinet FortiSandbox Threat Detection & Sandbox cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSandbox

Credit

Fortinet is pleased to thank Greg Roll for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiSandbox version 5.0.2 or above Upgrade to FortiSandbox version 4.4.8 or above

Something wrong here?