CVE-2023-47540OS Command Injection in Fortinet Fortisandbox

Severity
6.7MEDIUMNVD
EPSS
0.1%
top 66.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 9

Description

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.0.5 through 3.0.7 allows attacker to execute unauthorized code or commands via CLI.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortisandbox3.2.04.2.7+2
CVEListV5fortinet/fortisandbox4.4.04.4.2+4

🔴Vulnerability Details

2
GHSA
GHSA-564x-rr7c-f7qq: An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSandbox version 42024-04-09
CVEList
CVE-2023-47540: An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 42024-04-09

📋Vendor Advisories

1
Fortinet
FortiSandbox - Command injection impacting CLI command2024-04-09
CVE-2023-47540 — OS Command Injection in Fortinet | cvebase