CVE-2024-23671
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 throug
Description
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSandbox | Threat Detection & Sandbox | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiSandbox
- fortinet · fortisandbox
Credit
Internally discovered and reported by Adham El karn of Fortinet Product Security team.
Vendor remediation
Upgrade to FortiSandbox version 4.4.4 or above Upgrade to FortiSandbox version 4.2.7 or above Upgrade to FortiSandbox version 4.0.5 or above Fortinet remediated this issue in FortiSandbox Cloud version 24.1 and hence customers do not need to perform any action.