CVE-2024-52960

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 602

Summary

CVE-2024-52960 is a client-side security vulnerability affecting Fortinet FortiSandbox versions 5.0.0, 4.4.0 through 4.4.6, and older than 4.2.7. This issue, classified as CWE-602, enables an authenticated attacker with read-only permissions to execute unauthorized commands. The vulnerability arises due to a lack of proper enforcement of server-side security protocols on the client-side, posing a significant risk to affected systems. Successful exploitation could result in serious consequences, including potential data breaches and unauthorized system access. It is strongly recommended that users of FortiSandbox update to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share