cbcvebase.

Fortinet Fortisandbox vulnerabilities

60 known vulnerabilities affecting fortinet/fortisandbox.

Total CVEs
60
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL6HIGH24MEDIUM28LOW2

Vulnerabilities

Page 2 of 3
CVE-2024-23671P3HIGHCVSS 8.1≥ 4.0.0, < 4.0.5≥ 4.2.0, < 4.2.7+4 more2024-04-09
CVE-2024-23671 [HIGH] CWE-22 CVE-2024-23671: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
nvd
CVE-2020-29011P3HIGHCVSS 8.8fixed in 3.1.5≥ 3.2.0, < 3.2.22021-08-04
CVE-2020-29011 [HIGH] CWE-89 CVE-2020-29011: Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of Fort Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via specifically crafted HTTP requests.
nvd
CVE-2021-26096P3HIGHCVSS 8.8≤ 3.1.4≥ 3.2.0, < 3.2.32021-08-04
CVE-2021-26096 [HIGH] CWE-787 CVE-2021-26096: Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 m Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate memory and alter its content by means of specifically crafted command line arguments.
nvd
CVE-2022-30305P3HIGHCVSS 7.5≥ 3.1.0, ≤ 3.1.5≥ 4.0.0, ≤ 4.0.2+5 more2022-12-06
CVE-2022-30305 [HIGH] CWE-778 CVE-2022-30305: An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3. An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through 3.0.2 may allow a remote attacker to repeatedly enter incorrect credentials
nvd
CVE-2023-41682P3HIGHCVSS 7.5≥ 2.4.0, ≤ 2.4.1≥ 2.5.0, ≤ 2.5.2+7 more2023-10-13
CVE-2023-41682 [HIGH] CWE-22 CVE-2023-41682: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4 all versions allow
nvd
CVE-2022-27485P3MEDIUMCVSS 6.5≥ 3.0.1, ≤ 3.0.7≥ 3.1.0, < 3.2.4+5 more2023-04-11
CVE-2022-27485 [MEDIUM] CWE-89 CVE-2022-27485: A improper neutralization of special elements used in an sql command ('sql injection') vulnerability A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0, 4.0.0 through 4.0.2, 3.2.0 through 3.2.3, 3.1.x and 3.0.x allows a remote and authenticated attacker with read permission to retrieve arbitrary files from the underlying Linux system via a crafted HTTP
nvd
CVE-2022-26115P3HIGHCVSS 7.5v3.2.0v3.2.1+7 more2023-02-16
CVE-2022-26115 [HIGH] CWE-916 CVE-2022-26115: A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbo A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords.
nvd
CVE-2026-25691P3MEDIUMCVSS 6.7≥ 4.2.0, < 4.4.9≥ 5.0.0, < 5.0.6+3 more2026-04-14
CVE-2026-25691 [MEDIUM] CWE-22 CVE-2026-25691: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary d
nvd
CVE-2021-22124P3HIGHCVSS 7.5≥ 3.0.0, < 3.0.7≥ 3.1.0, < 3.1.5+1 more2021-08-04
CVE-2021-22124 [HIGH] CWE-400 CVE-2021-22124: An uncontrolled resource consumption (denial of service) vulnerability in the login modules of Forti An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring the device into an unresponsive state via specifically-crafted long request parameters.
nvd
CVE-2024-45328P3HIGHCVSS 7.8≥ 4.4.0, < 4.4.7≥ 4.4.0, ≤ 4.4.62025-03-11
CVE-2024-45328 [HIGH] CWE-863 CVE-2024-45328: An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a l An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu.
nvd
CVE-2021-22125P3HIGHCVSS 7.2fixed in 3.2.22021-07-20
CVE-2021-22125 [HIGH] CWE-78 CVE-2021-22125: An instance of improper neutralization of special elements in the sniffer module of FortiSandbox bef An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file.
nvd
CVE-2021-26098P3HIGHCVSS 7.5≤ 3.1.4≥ 3.2.0, < 3.2.32021-08-04
CVE-2021-26098 [HIGH] CWE-330 CVE-2021-26098: An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.
nvd
CVE-2024-31487P3MEDIUMCVSS 6.5≥ 2.4.0, < 4.2.7≥ 4.4.0, < 4.4.5+8 more2024-04-09
CVE-2024-31487 [MEDIUM] CWE-22 CVE-2024-31487: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4 all v
nvd
CVE-2024-27779P3MEDIUMCVSS 6.7≥ 3.2.0, < 4.2.7≥ 4.4.0, < 4.4.5+4 more2025-07-18
CVE-2024-27779 [MEDIUM] CWE-613 CVE-2024-27779: An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4. An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versions may allow a remote attacker in possession of an
nvd
CVE-2023-47540P3MEDIUMCVSS 6.7≥ 3.0.5, ≤ 3.0.7≥ 3.2.0, < 4.2.7+5 more2024-04-09
CVE-2023-47540 [MEDIUM] CWE-78 CVE-2023-47540: An improper neutralization of special elements used in an os command ('os command injection') vulner An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.0.5 through 3.0.7 allows attacker to execute unauthorized code or commands via CLI.
nvd
CVE-2024-31490P3MEDIUMCVSS 6.5≥ 3.2.2, < 4.2.7≥ 4.4.0, < 4.4.5+5 more2024-09-10
CVE-2024-31490 [MEDIUM] CWE-200 CVE-2024-31490: An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2.2 through 3.2.4, FortiSandbox 3.1.5 allows attacker to information disclosure via HTTP get requests.
nvd
CVE-2021-24010P3MEDIUMCVSS 6.5≥ 3.1.0, < 3.1.5≥ 3.2.0, < 3.2.32021-08-04
CVE-2021-24010 [MEDIUM] CWE-22 CVE-2021-24010: Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 th Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests.
nvd
CVE-2025-46215P3MEDIUMCVSS 5.3≥ 4.0.0, < 4.4.8≥ 5.0.0, < 5.0.2+4 more2025-11-18
CVE-2025-46215 [MEDIUM] CWE-653 CVE-2025-46215: An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.
nvd
CVE-2023-47541P4MEDIUMCVSS 6.7≥ 2.0.0, < 4.2.7≥ 4.4.0, < 4.4.3+12 more2024-04-09
CVE-2023-47541 [MEDIUM] CWE-22 CVE-2023-47541: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4 all
nvd
CVE-2025-54353P4MEDIUMCVSS 6.1≥ 4.0.0, ≤ 4.0.6≥ 4.2.0, ≤ 4.2.8+3 more2025-12-09
CVE-2025-54353 [MEDIUM] CWE-79 CVE-2025-54353: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.
nvd
Fortinet Fortisandbox vulnerabilities | cvebase