Fortinet FortiSandbox 5.0.0~5.0.5, FortiSandbox 4.4.0~4.4.8, FortiSandbox 4.2 모든 버전, FortiSandbox Cloud 5.0.4~5.0.5, FortiSandbox PaaS 5.0.4~5.0.5의 os 명령('os 명령 삽입')에 사용된 특수 요소를 부적절하게 무력화하면 다음이 허용될 수 있습니다. 특별히 제작된 HTTP 요청을 통해 인증되지 않은 명령을 실행하는 인증되지 않은 공격자
Fortinet FortiSandbox 5.0.05.0.5, FortiSandbox 4.4.04.4.8, FortiSandbox 4.2 모든 버전, FortiSandbox Cloud 5.0.45.0.5, FortiSandbox PaaS 5.0.45.0.5의 os 명령('os 명령 삽입')에 사용된 특수 요소를 부적절하게 무력화하면 다음이 허용될 수 있습니다. 특별히 제작된 HTTP 요청을 통해 인증되지 않은 명령을 실행하는 인증되지 않은 공격자
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 98.00 |
| 악용 신호(KEV 등재) | ×1.50 |
| VPI | 100.00 |
VPI 공식 vpi-v1 기준
필수 조치
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.