OS Command Injection Vulnerability in FortiSandbox by Fortinet
CVE-2024-54018

6.8MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
11 March 2025

Summary

Multiple issues related to improper neutralization of special elements used in OS command contexts have been identified in FortiSandbox prior to version 4.4.5. These vulnerabilities enable a privileged attacker to craft requests that can execute unauthorized commands on the affected system, potentially leading to data breaches or other malicious activities. It’s crucial for users to update their systems promptly to mitigate the risk associated with this exploit. For more details, refer to the official Fortinet advisory.

Affected Version(s)

FortiSandbox 4.4.0 <= 4.4.4

FortiSandbox 4.2.0 <= 4.2.6

FortiSandbox 4.0.0 <= 4.0.6

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.