SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-47540

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions,…

MEDIUM 6.7EPSS 0.63%

Does this matter?

Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.

Description

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.0.5 through 3.0.7 allows attacker to execute unauthorized code or commands via CLI.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.63% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
fortinet/fortisandbox
Source
psirt@fortinet.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.