FG-IR-24-305: Client-side enforcement of server-side security related to vm download feature
A client-side enforcement of server-side security vulnerability [CWE-602] in FortiSandbox may allow an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-305?
The severity of FG-IR-24-305 is critically concerning due to its potential for unauthorized command execution by authenticated attackers.
How do I fix FG-IR-24-305?
To fix FG-IR-24-305, update FortiSandbox to the latest version provided by Fortinet that includes the appropriate remedies.
Who is affected by FG-IR-24-305?
FG-IR-24-305 affects users of FortiSandbox versions 4.0 and earlier, as well as specific versions identified between 4.2.0 to 4.2.7, 4.4.0 to 4.4.6, and 5.0.1 and beyond.
What risks are associated with FG-IR-24-305?
Risks associated with FG-IR-24-305 include the possibility of attackers executing unauthorized commands which may compromise system integrity and security.
Is FG-IR-24-305 a client-side attack?
Yes, FG-IR-24-305 is a client-side enforcement of server-side security vulnerability, allowing exploitation through crafted requests.