CVE-2024-54018: OS Command Injection in administrative interface
Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests.
Other sources
Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox may allow a privileged attacker to execute unauthorized commands via crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54018?
CVE-2024-54018 is classified as a high severity vulnerability due to the potential for privileged attackers to execute unauthorized commands.
How do I fix CVE-2024-54018?
To mitigate CVE-2024-54018, users should upgrade FortiSandbox to version 4.4.6 or later.
What software versions are affected by CVE-2024-54018?
CVE-2024-54018 affects FortiSandbox versions up to 4.4.5.
Who can be impacted by CVE-2024-54018?
CVE-2024-54018 can impact organizations using affected versions of FortiSandbox that are exposed to untrusted input.
What is the nature of CVE-2024-54018 vulnerability?
CVE-2024-54018 involves multiple improper neutralization of special elements used in OS Command vulnerabilities.