Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
F
RL
O
RC
Changed
Affected products
- fortinet / fortisandbox4.4.8 – 4.4.8
- fortinet / fortisandbox4.4.7 – 4.4.7
- fortinet / fortisandbox4.4.6 – 4.4.6
- fortinet / fortisandbox4.4.5 – 4.4.5
- fortinet / fortisandbox4.4.4 – 4.4.4
- fortinet / fortisandbox4.4.3 – 4.4.3
- fortinet / fortisandbox4.4.2 – 4.4.2
- fortinet / fortisandbox4.4.1 – 4.4.1
- fortinet / fortisandbox4.4.0 – 4.4.0
- fortinet / fortisandbox4.4.0 – 4.4.9
- fortinet / fortisandboxpaas23.4.4350 – 23.4.4350
- fortinet / fortisandboxpaas23.3.4329 – 23.3.4329
- fortinet / fortisandboxpaas23.1.4245 – 23.1.4245
- fortinet / fortisandboxpaas22.2.4151 – 22.2.4151
- fortinet / fortisandboxpaas22.2.4134 – 22.2.4134
- fortinet / fortisandboxpaas22.1.4113 – 22.1.4113
- fortinet / fortisandboxpaas21.4.4072 – 21.4.4072
- fortinet / fortisandboxpaas21.3.4055 – 21.3.4055
- fortinet / fortisandboxpaas23.4.4374 – 23.4.4374
Exploits & proofs of concept
- nucleiFortinet FortiSandbox - Command Injectionby DhiyaneshDk
References
- VENDOR_ADVISORYhttps://fortiguard.fortinet.com/psirt/FG-IR-26-100
Updated 3m ago · 8 sources