Critical Fortinet FortiSandbox Flaw Enables Remote Code Execution
ID: 5cfee32e-7164-50b5-b74f-072a872d63b8
STIX ID: report--5cfee32e-7164-50b5-b74f-072a872d63b8
Feed Name: Cyber Press
Threat Score
A critical missing-authorization vulnerability (CWE-862) in Fortinet FortiSandbox—impacting multiple on-premises, Cloud, and PaaS releases—allows unauthenticated attackers to craft HTTP requests that can execute arbitrary code or system commands on the appliance; Fortinet published fixed releases and administrators are urged to upgrade or migrate to patched versions immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
