Impact
This vulnerability is an OS command injection that allows an unauthenticated attacker to execute arbitrary operating system commands on a FortiSandbox system. The flaw arises from improper neutralization of special elements used in an operating system command and is classified as CWE‑78. An attacker can craft specially designed HTTP requests to trigger the injection and gain full control of the underlying host, compromising confidentiality, integrity, and availability.
Affected Systems
Fortinet FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS are affected. Any instance running FortiSandbox version 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, or any 4.2.x release is vulnerable. FortiSandbox Cloud is vulnerable for versions 5.0.4 through 5.0.5, and FortiSandbox PaaS for versions 5.0.4 through 5.0.5.
Risk and Exploitability
The EPSS score of 74% indicates a high probability of exploitation in the wild, while the CVSS score of 9.1 reflects a very high severity impact. The flaw permits an unauthenticated attacker to execute arbitrary OS commands via specially crafted HTTP requests, granting full remote code execution. FortiSandbox Cloud does not require action now because Fortinet has remediated the issue in forthcoming releases; plan to upgrade once 5.0.6 becomes available. It has been added to CISA’s KEV catalog, underscoring the urgency due to the high CVSS score and the elevated EPSS.
OpenCVE Enrichment