CVE-2024-31491
published 2024-05-14CVE-2024-31491: A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.83%
53.4th percentile
A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | >= 4.2.0 < 4.2.7 | 4.2.7 |
| fortinet | fortisandbox | 4.2.1 – 4.2.6 | — |
| fortinet | fortisandbox | >= 4.4.0 < 4.4.5 | 4.4.5 |
| fortinet | fortisandbox | 4.4.0 – 4.4.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Readonly user could execute sensitive operations
vendor_fortinet·2024-05-14·CVSS 8.8
CVE-2024-31491 [HIGH] CWE-602 Readonly user could execute sensitive operations
FG-IR-24-054: Readonly user could execute sensitive operations
A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
CVEs: CVE-2024-31491
CWEs: CWE-602
CVSS: 8.8 (high)
Affected products: FortiSandbox, Fortinet
GHSA
GHSA-c9v5-8cvh-f6v3: A client-side enforcement of server-side security in Fortinet FortiSandbox version 4
ghsa_unreviewed·2024-05-14
CVE-2024-31491 [HIGH] CWE-602 GHSA-c9v5-8cvh-f6v3: A client-side enforcement of server-side security in Fortinet FortiSandbox version 4
A client-side enforcement of server-side security in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-14
Published