First published: Tue Mar 11 2025(Updated: )
An incorrect authorization vulnerability [CWE-863] in FortiSandbox may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSandbox Firmware | >=4.4.0<=4.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-24-261 is critical due to the potential for low privileged administrators to execute elevated CLI commands.
To fix FG-IR-24-261, upgrade FortiSandbox firmware to version 4.4.7 or later.
FG-IR-24-261 affects FortiSandbox versions between 4.4.0 and 4.4.6.
FG-IR-24-261 is an incorrect authorization vulnerability classified under CWE-863.
If FG-IR-24-261 is exploited, a low privileged administrator may gain unauthorized access to execute sensitive commands.