FortiSandbox Path Traversal Vulnerability Allows Unauthorized Code Execution
CVE-2024-23671
8.1HIGH
Summary
A vulnerability has been identified within Fortinet FortiSandbox that involves an improper limitation of a pathname, allowing path traversal to occur. This weakness exists in FortiSandbox versions 4.4.0 to 4.4.3, 4.2.0 to 4.2.6, and 4.0.0 to 4.0.4. An attacker could exploit this vulnerability to execute unauthorized commands or code by sending specially crafted HTTP requests. Organizations using the affected versions are encouraged to apply necessary security measures to prevent potential exploitation.
Affected Version(s)
FortiSandbox 4.4.0 <= 4.4.3
FortiSandbox 4.2.0 <= 4.2.6
FortiSandbox 4.0.0 <= 4.0.4
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved