CVE-2024-52960: Client-side enforcement of server-side security related to vm download feature
A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
Other sources
A client-side enforcement of server-side security vulnerability [CWE-602] in FortiSandbox may allow an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52960?
CVE-2024-52960 is classified as a client-side enforcement of server-side security vulnerability with moderate severity.
How do I fix CVE-2024-52960?
To mitigate CVE-2024-52960, upgrade Fortinet FortiSandbox to version 5.0.1 or higher, or 4.4.7 or higher for versions 4.4.0 through 4.4.6, and 4.2.8 or higher for versions from 4.2.0 to 4.2.7.
What versions of Fortinet FortiSandbox are affected by CVE-2024-52960?
Fortinet FortiSandbox versions 4.4.0 through 4.4.6 and all versions prior to 4.2.7 are affected by CVE-2024-52960.
Can an unauthenticated user exploit CVE-2024-52960?
No, only an authenticated user with at least read-only permissions can exploit CVE-2024-52960.
What type of vulnerability is CVE-2024-52960?
CVE-2024-52960 is a client-side enforcement of server-side security vulnerability, indicating that it allows unauthorized commands to be executed via crafted requests.