PT-2024-3561 · Fortinet · Fortisandbox
Published
2024-05-14
·
Updated
2025-01-02
·
CVE-2024-31491
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiSandbox versions 4.2.0 through 4.2.6
FortiSandbox versions 4.4.0 through 4.4.4
Description
The issue is related to the client-side enforcement of server-side security in FortiSandbox. It allows an attacker to execute unauthorized code or commands via HTTP requests. This can potentially enable a malicious user to alter the device's configuration.
Recommendations
For FortiSandbox versions 4.2.0 through 4.2.6, update to a version outside of this range to resolve the issue.
For FortiSandbox versions 4.4.0 through 4.4.4, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to HTTP requests until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortisandbox