Fortinet FortiSandbox
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*
- >= 5.0.0, <= 5.0.5
- >= 4.4.0, <= 4.4.8
- >= 4.2, <= 4.2
A vulnerability allowing OS command injection has been identified in Fortinet FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8, all versions of 4.2, as well as FortiSandbox Cloud and FortiSandbox PaaS versions 5.0.4 to 5.0.5. This vulnerability allows an unauthenticated attacker to execute unauthorized commands by sending specially crafted HTTP requests.
Exploitation of this vulnerability could lead to unauthorized execution of commands on the affected system.
Users can upgrade Fortinet FortiSandbox to version 5.0.6 or 4.4.9, depending on their current version. FortiSandbox Cloud and FortiSandbox PaaS users should also upgrade to version 5.0.6.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.