CVE-2024-54027: Use of hardcoded key used for remote backup server password encryption
A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.
Other sources
A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54027?
The severity of CVE-2024-54027 is high due to the potential unauthorized access to sensitive data by a privileged attacker.
How do I fix CVE-2024-54027?
To fix CVE-2024-54027, update FortiSandbox to a version that corrects the vulnerability.
Who is affected by CVE-2024-54027?
CVE-2024-54027 affects users of FortiSandbox versions 3.0.5 to 5.0.1 who have a super-admin profile.
What type of vulnerability is CVE-2024-54027?
CVE-2024-54027 is a Use of Hard-coded Cryptographic Key vulnerability, classified as CWE-321.
What impact does CVE-2024-54027 have?
CVE-2024-54027 may allow attackers to read sensitive data through the command line interface.