CVE-2025-46215
BaseFortify
Publication date: 2025-11-18
Last updated on: 2025-11-20
Assigner: Fortinet, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortisandbox | From 5.0.0 (inc) to 5.0.3 (inc) |
| fortinet | fortisandbox | From 5.0.0 (inc) to 5.0.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-653 | The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Isolation or Compartmentalization issue in Fortinet FortiSandbox versions 4.0 through 5.0.1. It allows an unauthenticated attacker to bypass the sandbox scanning process by using a specially crafted file, meaning the sandbox may fail to detect malicious content.
How can this vulnerability impact me? :
The vulnerability can allow attackers to evade detection by the FortiSandbox security system, potentially leading to malicious files being executed or spreading without being identified. This could result in increased risk of compromise or infection within the protected environment.