CVE-2024-52961
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-52961 is a newly disclosed vulnerability affecting Fortinet FortiSandbox versions 5.0.0, 4.4.0-4.4.7, and before 4.0.5. This issue, classified as CWE-78 (Improper Neutralization of Special Elements Used in an OS Command), grants authenticated attackers with read-only permissions the ability to execute unauthorized OS commands through crafted requests. Successful exploitation of this vulnerability could lead to significant security implications for affected organizations. Fortinet urges users to update their FortiSandbox installations as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiSandbox
Affected Vendors
- Fortinet