Impact
An OS command injection flaw (CWE‑78) exists in Fortinet FortiSandbox Cloud and FortiSandbox PaaS version 5.0.4. The flaw occurs when special elements used in an operating‑system command are not properly neutralized, allowing a privileged attacker with a super‑admin profile and command‑line interface access to send crafted HTTP requests that cause the platform to execute arbitrary commands on the underlying host. This can lead to execution of arbitrary code with the privileges of the appliance, potentially resulting in full system compromise.
Affected Systems
The vulnerable products are Fortinet FortiSandbox Cloud version 5.0.4 and FortiSandbox PaaS version 5.0.4. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not recorded in the CISA KEV catalog. Exploitation requires the attacker to already possess super‑admin credentials and command‑line interface access, limiting the risk primarily to insider threats or compromised privileged accounts, but the impact could be extensive if such access is gained.
OpenCVE Enrichment