OS Command Vulnerability in Fortinet FortiSandbox
CVE-2024-52961
8.6HIGH
What is CVE-2024-52961?
An OS Command injection vulnerability exists in Fortinet FortiSandbox where an authenticated attacker with read-only permissions can execute unauthorized commands. By sending specially crafted requests, the attacker exploits improper neutralization of special elements, resulting in potential unauthorized access to system functionalities. This vulnerability affects multiple versions of Fortinet FortiSandbox, underscoring the need for immediate patching and security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FortiSandbox 5.0.0
FortiSandbox 4.4.0 <= 4.4.6
FortiSandbox 4.2.1 <= 4.2.7
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved