Vulnerability Fixed in Fortinet FortiSandbox (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Fortinet patches vulnerability in FortiSandbox and FortiSandbox PaaS
- Missing authorization allows code execution via HTTP requests
- Patch recommended for all affected versions
"Fortinet has fixed a vulnerability in FortiSandbox and FortiSandbox PaaS affecting multiple versions. The missing authorization allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests. This can lead to remote code execution, compromising system integrity."
no comments yet.