FG-IR-24-261: Incorrect authorization in GUI console
Published Mar 11, 2025
·Updated
An incorrect authorization vulnerability [CWE-863] in FortiSandbox may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu.
Affected Software
1 affected componentFixes available
Fortinet FortiSandbox>=4.4.0<=4.4.6
Event History
Mar 11, 2025
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-261?
The severity of FG-IR-24-261 is critical due to the potential for low privileged administrators to execute elevated CLI commands.
2
How do I fix FG-IR-24-261?
To fix FG-IR-24-261, upgrade FortiSandbox firmware to version 4.4.7 or later.
3
Who is affected by FG-IR-24-261?
FG-IR-24-261 affects FortiSandbox versions between 4.4.0 and 4.4.6.
4
What type of vulnerability is FG-IR-24-261?
FG-IR-24-261 is an incorrect authorization vulnerability classified under CWE-863.
5
What can happen if FG-IR-24-261 is exploited?
If FG-IR-24-261 is exploited, a low privileged administrator may gain unauthorized access to execute sensitive commands.