PT-2024-3042 · Fortinet · Fortisandbox

Published

2024-04-09

·

Updated

2024-12-23

·

CVE-2024-21755

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Fortinet FortiSandbox versions 4.0.0 through 4.0.4 Fortinet FortiSandbox versions 4.2.0 through 4.2.6 Fortinet FortiSandbox versions 4.4.0 through 4.4.3
Description The issue exists due to improper neutralization of special elements used in an os command, also known as 'os command injection'. This allows a remote attacker to execute unauthorized code or commands via crafted requests.
Recommendations For Fortinet FortiSandbox versions 4.0.0 through 4.0.4, update to a version that fixes the 'os command injection' issue. For Fortinet FortiSandbox versions 4.2.0 through 4.2.6, update to a version that fixes the 'os command injection' issue. For Fortinet FortiSandbox versions 4.4.0 through 4.4.3, update to a version that fixes the 'os command injection' issue. As a temporary workaround, consider restricting access to the vulnerable os command functionality until a patch is available.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-03226
CVE-2024-21755

Affected Products

Fortisandbox