FG-IR-24-054: Readonly user could execute sensitive operations
A client-side enforcement of server-side security vulnerability [CWE-602] in FortiSandbox may allow an authenticated attacker with at least read-only permission to download or upload configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-054?
The severity of FG-IR-24-054 is significant due to the potential for authenticated attackers to manipulate configuration settings.
How do I fix FG-IR-24-054?
To fix FG-IR-24-054, upgrade to the appropriate patched versions of FortiSandbox as specified in the advisory.
What versions of FortiSandbox are affected by FG-IR-24-054?
Versions of FortiSandbox ranging from 4.4.0 to 4.4.4 and 4.2.0 to 4.2.6 are affected by FG-IR-24-054.
What type of vulnerability is FG-IR-24-054?
FG-IR-24-054 is a client-side enforcement of server-side security vulnerability classified under CWE-602.
Who is at risk due to FG-IR-24-054?
Authenticated users with at least read-only permission on affected FortiSandbox versions are at risk due to FG-IR-24-054.