CVE-2024-27778: OS command injection
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiSandbox may allow an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
Other sources
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0.5 through 3.0.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27778?
CVE-2024-27778 is classified as a high severity vulnerability due to its potential for unauthorized command execution.
How do I fix CVE-2024-27778?
To fix CVE-2024-27778, upgrade Fortinet FortiSandbox to version 4.4.5 or above, 4.2.7 or above, or any version above 4.0.4.
What kind of vulnerability is CVE-2024-27778?
CVE-2024-27778 is an OS Command Injection vulnerability that arises from improper neutralization of special elements.
Who can exploit CVE-2024-27778?
An authenticated attacker with at least read-only permission can exploit CVE-2024-27778 to execute unauthorized commands.
Which versions of Fortinet FortiSandbox are affected by CVE-2024-27778?
Fortinet FortiSandbox versions 4.4.0 through 4.4.4, 4.2.0 through 4.2.6, and below 4.0.4 are affected by CVE-2024-27778.