CVE-2024-21756: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted requests..
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21756?
CVE-2024-21756 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-21756?
To fix CVE-2024-21756, you should update Fortinet FortiSandbox to the latest version that is not affected by this vulnerability.
What are the affected versions in CVE-2024-21756?
CVE-2024-21756 affects Fortinet FortiSandbox versions 4.0.0 through 4.0.4, 4.2.0 through 4.2.6, and 4.4.0 through 4.4.3.
What type of vulnerability is CVE-2024-21756?
CVE-2024-21756 is an OS command injection vulnerability that allows attackers to execute unauthorized commands.
Who is impacted by CVE-2024-21756?
Organizations using vulnerable versions of Fortinet FortiSandbox are at risk of exploitation due to CVE-2024-21756.