FG-IR-24-061: OS command injection
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiSandbox may allow an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-061?
The severity of FG-IR-24-061 is high due to the vulnerability allowing unauthorized command execution.
How do I fix FG-IR-24-061?
To fix FG-IR-24-061, upgrade to FortiSandbox versions 4.4.5, 4.2.7, or 4.0.5 or higher.
Who is affected by FG-IR-24-061?
Users running vulnerable versions of FortiSandbox, specifically versions 4.4.4, 4.2.6, 4.0.4, 3.2, and 3.1 are affected by FG-IR-24-061.
What type of vulnerability is FG-IR-24-061?
FG-IR-24-061 is classified as an improper neutralization of special elements used in an OS command vulnerability.
Can an attacker exploit FG-IR-24-061 without authentication?
No, an attacker requires at least read-only permission to exploit the FG-IR-24-061 vulnerability.