Impact
This vulnerability is an OS command injection flaw that allows an unauthenticated attacker to execute arbitrary operating‑system commands on a FortiSandbox appliance via specially crafted HTTP requests. The flaw arises from improper neutralization of special elements used in an OS command, giving the attacker full remote code execution capability and the potential to compromise system integrity and confidentiality. The weakness is categorized as CWE‑78.
Affected Systems
The affected products are Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. Any instance running FortiSandbox versions 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, and 4.2.x is vulnerable. FortiSandbox Cloud versions 5.0.4 through 5.0.5 and FortiSandbox PaaS versions 5.0.4 through 5.0.5 also expose the flaw.
Risk and Exploitability
The CVSS score for this issue is 9.1, indicating high severity. The EPSS score is not available, but the vulnerability is documented as publicly known with no restriction on prerequisites. It appears the attack vector is via unauthenticated HTTP requests sent to vulnerable endpoints, enabling remote code execution. The vulnerability is not listed in CISA’s KEV catalog, but the high CVSS suggests it should be treated with priority.
OpenCVE Enrichment