OS Command Injection Vulnerability in FortiSandbox by Fortinet
CVE-2024-54018
6.8MEDIUM
Summary
Multiple issues related to improper neutralization of special elements used in OS command contexts have been identified in FortiSandbox prior to version 4.4.5. These vulnerabilities enable a privileged attacker to craft requests that can execute unauthorized commands on the affected system, potentially leading to data breaches or other malicious activities. It’s crucial for users to update their systems promptly to mitigate the risk associated with this exploit. For more details, refer to the official Fortinet advisory.
Affected Version(s)
FortiSandbox 4.4.0 <= 4.4.4
FortiSandbox 4.2.0 <= 4.2.6
FortiSandbox 4.0.0 <= 4.0.6
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved