Client-side enforcement of server-side security related to vm download feature

Summary

A client-side enforcement of server-side security vulnerability [CWE-602] in FortiSandbox may allow an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.

Version Affected Solution
FortiSandbox 5.0 5.0.0 Upgrade to 5.0.1 or above
FortiSandbox 4.4 4.4.0 through 4.4.6 Upgrade to 4.4.7 or above
FortiSandbox 4.2 4.2.1 through 4.2.7 Upgrade to 4.2.8 or above
FortiSandbox 4.0 4.0 all versions Migrate to a fixed release
FortiSandbox 3.2 3.2 all versions Migrate to a fixed release
FortiSandbox 3.1 3.1 all versions Migrate to a fixed release
FortiSandbox 3.0 3.0 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2025-03-11: Initial publication