First published: Tue Apr 09 2024(Updated: )
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 through 4.4.2 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 and 2.5.0 through 2.5.2 and 2.4.0 through 2.4.1 and 2.3.0 through 2.3.3 and 2.2.0 through 2.2.2 and 2.1.0 through 2.1.3 and 2.0.0 through 2.0.3 allows attacker to execute unauthorized code or commands via CLI.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSandbox | >=4.4.0<=4.4.2 | |
Fortinet FortiSandbox | >=4.2.0<=4.2.6 | |
Fortinet FortiSandbox | >=4.0 | |
Fortinet FortiSandbox | >=3.2 | |
Fortinet FortiSandbox | >=3.1 | |
Fortinet FortiSandbox | >=3.0 | |
Fortinet FortiSandbox | >=2.5 | |
Fortinet FortiSandbox | >=2.4 | |
Fortinet FortiSandbox | >=2.3 | |
Fortinet FortiSandbox | >=2.2 | |
Fortinet FortiSandbox | >=2.1 | |
Fortinet FortiSandbox | >=2.0 | |
Fortinet FortiSandbox | >=2.0.0<4.2.7 | |
Fortinet FortiSandbox | >=4.4.0<4.4.3 |
Please upgrade to FortiSandbox version 4.4.3 or above Please upgrade to FortiSandbox version 4.2.7 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47541 has been classified as a critical vulnerability due to its potential for remote exploitation.
To resolve CVE-2023-47541, upgrade Fortinet FortiSandbox to version 4.4.3 or later, or 4.2.7 or later.
CVE-2023-47541 affects Fortinet FortiSandbox versions 4.4.0 through 4.4.2, 4.2.0 through 4.2.6, and multiple earlier versions.
CVE-2023-47541 is categorized as a path traversal vulnerability.
Yes, successful exploitation of CVE-2023-47541 may lead to unauthorized access to sensitive files.