PT-2024-3561 · Fortinet · Fortisandbox

Published

2024-05-14

·

Updated

2025-01-02

·

CVE-2024-31491

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiSandbox versions 4.2.0 through 4.2.6 FortiSandbox versions 4.4.0 through 4.4.4
Description The issue is related to the client-side enforcement of server-side security in FortiSandbox. It allows an attacker to execute unauthorized code or commands via HTTP requests. This can potentially enable a malicious user to alter the device's configuration.
Recommendations For FortiSandbox versions 4.2.0 through 4.2.6, update to a version outside of this range to resolve the issue. For FortiSandbox versions 4.4.0 through 4.4.4, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to HTTP requests until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-03866
CVE-2024-31491

Affected Products

Fortisandbox