Impact
An OS command injection flaw (CWE-78) exists in Fortinet FortiSandbox Cloud 5.0.4 where the system fails to neutralize special elements in an os command. An attacker who has super‑admin privileges and CLI access can craft a malicious HTTP request that causes the platform to run arbitrary commands on the host, resulting in unauthorized code execution with the appliance's privileges and the potential for full system compromise.
Affected Systems
The affected product is Fortinet FortiSandbox Cloud version 5.0.4. The related CPE identifiers reference this version, and no other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.7 signifies moderate severity, while the EPSS of less than 1% suggests a low likelihood of exploitation. The vulnerability does not appear in the CISA KEV catalog. Exploitation requires attackers to already possess super‑admin credentials and CLI access, limiting risk to insiders or compromised accounts but still representing a significant threat if such access is obtained.
OpenCVE Enrichment