- Description
- An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
- Source
- psirt@fortinet.com
- NVD status
- Modified
- Products
- fortisandbox
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- psirt@fortinet.com
- CWE-78
- Hype score
- Not currently trending
Fortinet Addresses Multiple Vulnerabilities in FortiSandbox, FortiOS | Read more: https://t.co/OQPWF08TOo 📌 OS Command vulnerability – CVE-2024-52961 📌 Incorrect authorization vulnerability – CVE-2024-45328 📌 Format String Vulnerability – CVE-2024-45324 📌 SQL injection… http
@The_Cyber_News
13 Mar 2025
278 Impressions
0 Retweets
0 Likes
2 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2024-52961 🔴 HIGH (8.6) 🏢 Fortinet - FortiSandbox 🏗️ 5.0.0 🔗 https://t.co/0GiLCpsGAZ #CyberCron #VulnAlert #InfoSec https://t.co/HWbhr288eN
@cybercronai
12 Mar 2025
79 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
1 Quote
CVE-2024-52961 An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.7, 4.2.0 through… https://t.co/KrrcElM8QY
@CVEnew
11 Mar 2025
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "145ED28B-323B-4B4C-8E88-98FDBDAA86E1",
"versionEndExcluding": "4.0.6",
"versionStartIncluding": "3.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A19FD0B7-EB27-4118-944C-BF38648A7A0F",
"versionEndExcluding": "4.2.8",
"versionStartIncluding": "4.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2DB040DB-3A14-40ED-A79A-751E415CF496",
"versionEndExcluding": "4.4.7",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A76F978E-2082-45A0-93FE-107B0BAFE0C3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]