Improper Neutralization Vulnerability in FortiSandbox by Fortinet
CVE-2021-22125

6.3MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
20 July 2021

Summary

An improper neutralization vulnerability exists in the sniffer module of FortiSandbox that could allow an authenticated administrator to manipulate the configuration file. This manipulation can lead to unauthorized command execution on the system's underlying shell, posing a significant security risk. Organizations using vulnerable versions of FortiSandbox should apply the necessary updates to mitigate potential exploits.

Affected Version(s)

Fortinet FortiSandbox FortiSandbox before 3.2.2

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.