CVE-2024-54027

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and belo

Severity
High 7.8
CVSS 3.1
Exploited
Not listed
EPSS
0.002
5.0th percentile
Discovered by
Vendor
Vendor advisory field
Published
Mar 17, 2025
Assigned by fortinet

Description

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.

Weakness: CWE-321

Affected products

Vendor Product Category Matched by
Fortinet FortiSandbox Threat Detection & Sandbox cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSandbox

Credit

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Vendor remediation

Upgrade to FortiSandbox version 5.0.1 or above Upgrade to FortiSandbox version 4.4.7 or above Upgrade to FortiSandbox version 4.2.8 or above Upgrade to FortiSandbox version 4.0.6 or above

Something wrong here?