FG-IR-24-327: Use of hardcoded key used for remote backup server password encryption
Published Mar 11, 2025
·Updated
A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.
Affected Software
7 affected componentsFixes available
Fortinet FortiSandbox=.
Fortinet FortiSandbox>=4.4.0<=4.4.6
Fortinet FortiSandbox>=4.2.0<=4.2.7
Fortinet FortiSandbox>=4.0.0<=4.0.5
Fortinet FortiSandbox>=3.2
Fortinet FortiSandbox>=3.1
Fortinet FortiSandbox>=3.0.5<=3.0.7
Event History
Mar 11, 2025
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-327?
The severity of FG-IR-24-327 is significant as it allows a privileged attacker to access sensitive data.
2
How do I fix FG-IR-24-327?
To fix FG-IR-24-327, upgrade your FortiSandbox to the latest firmware version as specified in the vendor's advisory.
3
Which versions of FortiSandbox are affected by FG-IR-24-327?
Affected versions of FortiSandbox include those prior to 5.0.1, 4.4.7, 4.2.8, and 4.0.6 as well as specific ranges in earlier versions.
4
Who can exploit FG-IR-24-327?
Only an attacker with super-admin profile and CLI access can exploit FG-IR-24-327.
5
What type of vulnerability is FG-IR-24-327?
FG-IR-24-327 is classified as a Use of Hard-coded Cryptographic Key vulnerability.