Fortinet FortiSandbox 4.4.4

CPE Details

Fortinet FortiSandbox 4.4.4
4.4.4
2024-12-11
15h20 +00:00
2024-12-11
15h20 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortisandbox

Version

4.4.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-27778 2025-01-14 14h09 +00:00 An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in Fortinet FortiSandbox version 4.4.0 through 4.4.4, 4.2.0 through 4.2.6 and below 4.0.4 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
8.8
High
CVE-2024-31490 2024-09-10 14h37 +00:00 An exposure of sensitive information to an unauthorized actor in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.2 through 3.2.4 and 3.1.5 allows attacker to information disclosure via HTTP get requests.
6.5
Medium
CVE-2024-31491 2024-05-14 16h19 +00:00 A client-side enforcement of server-side security in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
8.8
High
CVE-2024-31487 2024-04-09 14h24 +00:00 A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 and 2.5.0 through 2.5.2 and 2.4.0 through 2.4.1 may allows attacker to information disclosure via crafted http requests.
6.5
Medium