CVE-2024-45328: Incorrect authorization in GUI console
An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu.
Other sources
An incorrect authorization vulnerability [CWE-863] in FortiSandbox may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45328?
CVE-2024-45328 is categorized as a medium severity vulnerability impacting FortiSandbox versions 4.4.0 through 4.4.6.
How do I fix CVE-2024-45328?
To fix CVE-2024-45328, upgrade FortiSandbox to version 4.4.7 or later.
Who is impacted by CVE-2024-45328?
CVE-2024-45328 affects low privileged administrators using FortiSandbox versions 4.4.0 to 4.4.6.
What can attackers do with CVE-2024-45328?
Attackers can exploit CVE-2024-45328 to execute elevated CLI commands through the GUI console menu.
What type of vulnerability is CVE-2024-45328 classified as?
CVE-2024-45328 is classified as an incorrect authorization vulnerability, specifically identified as CWE-863.