Fortinet FortiSandbox
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*
- 5.0.4
A path traversal vulnerability has been identified in Fortinet FortiSandbox versions 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, and all versions of FortiSandbox 4.2. Additionally, FortiSandbox Cloud 5.0.4 and FortiSandbox PaaS 5.0.4 are affected. This vulnerability allows a privileged attacker with a super-admin profile and CLI access to delete arbitrary directories by sending crafted HTTP requests.
Exploitation of this vulnerability could lead to unauthorized deletion of directories, potentially causing data loss or disruption of service.
Users of Fortinet FortiSandbox 5.0.0 through 5.0.5 should upgrade to 5.0.6 or above. Users of Fortinet FortiSandbox 4.4.0 through 4.4.8 should upgrade to 4.4.9 or above. Fortinet FortiSandbox 4.2 users should migrate to a fixed release. For Fortinet FortiSandbox Cloud 5.0.4, no action is needed as the issue has been remediated in 5.0.5. Fortinet FortiSandbox PaaS 5.0.4 users should upgrade to 5.0.5 or above.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.