PT-2024-3042 · Fortinet · Fortisandbox

CVE-2024-21755

·

Published

2024-04-09

·

Updated

2024-12-23

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Fortinet FortiSandbox versions 4.0.0 through 4.0.4 Fortinet FortiSandbox versions 4.2.0 through 4.2.6 Fortinet FortiSandbox versions 4.4.0 through 4.4.3
Description The issue exists due to improper neutralization of special elements used in an os command, also known as 'os command injection'. This allows a remote attacker to execute unauthorized code or commands via crafted requests.
Recommendations For Fortinet FortiSandbox versions 4.0.0 through 4.0.4, update to a version that fixes the 'os command injection' issue. For Fortinet FortiSandbox versions 4.2.0 through 4.2.6, update to a version that fixes the 'os command injection' issue. For Fortinet FortiSandbox versions 4.4.0 through 4.4.3, update to a version that fixes the 'os command injection' issue. As a temporary workaround, consider restricting access to the vulnerable os command functionality until a patch is available.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03226
CVE-2024-21755

Affected Products

Fortisandbox