FortiSandbox Path Traversal Vulnerability Allows Unauthorized Code Execution
CVE-2024-23671
8.1HIGH
What is CVE-2024-23671?
A vulnerability has been identified within Fortinet FortiSandbox that involves an improper limitation of a pathname, allowing path traversal to occur. This weakness exists in FortiSandbox versions 4.4.0 to 4.4.3, 4.2.0 to 4.2.6, and 4.0.0 to 4.0.4. An attacker could exploit this vulnerability to execute unauthorized commands or code by sending specially crafted HTTP requests. Organizations using the affected versions are encouraged to apply necessary security measures to prevent potential exploitation.
Affected Version(s)
FortiSandbox 4.4.0 <= 4.4.3
FortiSandbox 4.2.0 <= 4.2.6
FortiSandbox 4.0.0 <= 4.0.4