CVE-2024-52961: Os command injection on vm download feature
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiSandbox may allow an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
Other sources
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52961?
The severity of CVE-2024-52961 is classified as high, allowing potential unauthorized command execution.
How do I fix CVE-2024-52961?
To fix CVE-2024-52961, upgrade Fortinet FortiSandbox to version 5.0.1 or later, or to 4.4.7 or later, depending on the current version.
Who is affected by CVE-2024-52961?
CVE-2024-52961 affects Fortinet FortiSandbox versions 4.4.0 through 4.4.7, 4.2.0 through 4.2.7, and below version 4.0.5.
What type of vulnerability is CVE-2024-52961?
CVE-2024-52961 is classified as an improper neutralization of special elements used in an OS Command injection vulnerability.
What can an attacker do with CVE-2024-52961?
An authenticated attacker with read-only permissions can execute unauthorized commands on the affected Fortinet FortiSandbox systems.