FG-IR-24-306: Os command injection on vm download feature
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiSandbox may allow an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-306?
The severity of FG-IR-24-306 is classified as critical due to its potential to allow unauthorized command execution.
How do I fix FG-IR-24-306?
To fix FG-IR-24-306, update FortiSandbox to the latest version as specified in the vendor's advisory.
Who is affected by FG-IR-24-306?
FG-IR-24-306 affects Fortinet FortiSandbox versions ranging from 3.0 to 5.0.1, depending on specific subversions.
What type of vulnerability is FG-IR-24-306?
FG-IR-24-306 is an improper neutralization of special elements used in an OS Command vulnerability, identified as CWE-78.
What access level is required to exploit FG-IR-24-306?
An authenticated attacker with at least read-only permission can exploit FG-IR-24-306.