PT-2025-10780 · Fortinet · Fortisandbox

Published

2025-03-11

·

Updated

2025-07-23

·

CVE-2024-54018

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: FortiSandbox versions prior to 4.4.5
Description: The issue is related to improper neutralization of special elements used in an OS Command, allowing a privileged attacker to execute unauthorized commands via crafted requests.
Recommendations: For versions prior to 4.4.5, update to version 4.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-03649
CVE-2024-54018

Affected Products

Fortisandbox