CVE-2024-52961

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 78

Summary

CVE-2024-52961 is a newly disclosed vulnerability affecting Fortinet FortiSandbox versions 5.0.0, 4.4.0-4.4.7, and before 4.0.5. This issue, classified as CWE-78 (Improper Neutralization of Special Elements Used in an OS Command), grants authenticated attackers with read-only permissions the ability to execute unauthorized OS commands through crafted requests. Successful exploitation of this vulnerability could lead to significant security implications for affected organizations. Fortinet urges users to update their FortiSandbox installations as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share