ZeroHour

CVE-2024-27781

moderate

Authenticated Cross-Site Scripting in Fortinet FortiSandbox allows code execution

CVSS 3.1
9.0 critical
EPSS
28%p98
Published
()
Modified
AI analysis

CVE-2024-27781 is an input neutralization flaw (cross-site scripting, CWE-79) in the Fortinet FortiSandbox web interface. An authenticated attacker sends crafted HTTP requests that get embedded into generated web pages without proper sanitization, allowing execution of unauthorized code or commands in the context of the affected web UI. Because the CVSS scope is changed (S:C) with high confidentiality, integrity and availability impacts, successful exploitation can compromise the victim's browser session and extend beyond the vulnerable component. The flaw affects FortiSandbox across the 3.0, 3.1, 3.2, 4.0, 4.2 and 4.4 release trains, so essentially any unpatched appliance on those versions is exposed to an attacker with valid credentials to the interface. Exploitation has not been observed publicly (no KEV entry, no known public PoC), but the EPSS score of 28.2% (98th percentile) indicates a materially elevated probability of exploitation within the next 30 days.

What to do: Upgrade FortiSandbox to a patched release beyond the affected ranges (newer than 4.4.4/4.2.6/4.0.4 for those trains, and off 3.x versions), following Fortinet's PSIRT advisory for CVE-2024-27781. In the interim, restrict access to the FortiSandbox web UI to trusted management networks and limit the number of privileged accounts. Prioritize patching on internet-reachable appliances and monitor for exploitation attempts given the elevated 28.2% EPSS score.

Affected
fortinet FortiSandbox4.4.0 through 4.4.4
fortinet FortiSandbox4.2.1 through 4.2.6
fortinet FortiSandbox4.0.0 through 4.0.4
fortinet FortiSandbox3.2, all versions
fortinet FortiSandbox3.1, all versions
fortinet FortiSandbox3.0, all versions
Estimated exposure
moderatelikely tens of thousands of appliance deployments worldwide (no published install counts) — FortiSandbox is a dedicated enterprise sandboxing appliance whose installed base is far smaller than Fortinet's multi-million-unit FortiGate line, and internet-exposed scans and typical enterprise deployment patterns suggest deployments in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

Vendors
fortinet
Products
fortisandbox
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.