Impact
A directory traversal flaw allows an attacker to specify paths outside the intended sandbox environment, enabling them to access or modify files that are normally protected. This can break out of the sandbox and grant the attacker higher privileges, potentially compromising the host system and all data it manages. The weakness is a classic path traversal issue.
Affected Systems
Fortinet FortiSandbox and FortiSandbox Cloud are affected. Versions 4.4.0 through 4.4.8 and 5.0.0 through 5.0.5 are vulnerable. The issue exists in both the on‑premises FortiSandbox appliance and the cloud service.
Risk and Exploitability
The CVSS base score of 9.1 marks this flaw as critical. No EPSS score is available, and it is not listed in the CISA KEV catalog, so the exact exploitation frequency is unclear. The likely path to exploitation involves a network‑reachable interface where the attacker can supply a crafted path that includes '../' sequences to escape the sandbox. Once the traversal is successful, the attacker can gain elevated privileges on the FortiSandbox host.
OpenCVE Enrichment