Impact
A command injection weakness exists in Fortinet FortiSandbox due to improper neutralization of special elements used in a command. This flaw allows an attacker to inject and execute arbitrary system commands on the FortiSandbox host, potentially compromising the entire sandbox environment. The vulnerability is identified as CWE‑77 and could lead to loss of data confidentiality, integrity, and availability if exploited.
Affected Systems
The affected products are Fortinet FortiSandbox versions 5.2.0, 5.0.0 through 5.0.6, and 4.4.0 through 4.4.9. Any deployment using these legacy releases is susceptible unless upgraded to a supported version. The vendor provides separate patch release paths for the 5.x and 4.x branches, with the newest corrective releases being 5.2.1, 5.0.7, and 4.4.10 respectively.
Risk and Exploitability
The CVSS base score of 6.7 reflects moderate severity; EPSS information is unavailable, so actual exploitation likelihood is unknown. The flaw is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector is not explicitly detailed in the advisory, but it is inferred that an attacker must be able to submit input that reaches the vulnerable command construction, such as uploading a malicious file or sending a crafted API request. Once achieved, the attacker can execute arbitrary commands with the privileges of the FortiSandbox service, posing a serious threat to systems that rely on sandbox isolation.
OpenCVE Enrichment