CVE-2024-31491
A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands
Severity
High 8.6
CVSS 3.1
Exploited
Not listed
EPSS
0.008
56.2th percentile
Discovered by
Vendor
Vendor advisory field
Published
May 14, 2024
Assigned by fortinet
Description
A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
Weakness: CWE-602
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSandbox | Threat Detection & Sandbox | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiSandbox
- fortinet · fortisandbox
Credit
Internally discovered and reported by Adham El karn of Fortinet Product Security team.
Vendor remediation
Fortinet remediated this issue in FortiSandbox Cloud version 24.1 and hence customers do not need to perform any action. Upgrade to FortiSandbox version 4.4.5 or above Upgrade to FortiSandbox version 4.2.7 or above