CVE-2024-52961

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*

History

14 Jan 2026, 15:15

Type Values Removed Values Added
Summary (en) An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.7, 4.2.0 through 4.2.7 and before 4.0.5 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests. (en) An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.

23 Jul 2025, 15:07

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:5.0.0:*:*:*:*:*:*:*
Summary
  • (es) Una neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de comando del sistema operativo [CWE-78] en Fortinet FortiSandbox versión 5.0.0, 4.4.0 a 4.4.7, 4.2.0 a 4.2.7 y anteriores a 4.0.5 permite que un atacante autenticado con al menos permiso de solo lectura ejecute comandos no autorizados a través de solicitudes manipuladas.
First Time Fortinet
Fortinet fortisandbox
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-306 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-306 - Vendor Advisory

11 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 15:15

Updated : 2026-01-14 15:15


NVD link : CVE-2024-52961

Mitre link : CVE-2024-52961

CVE.ORG link : CVE-2024-52961


JSON object : View

Products Affected

fortinet

  • fortisandbox
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')