Fortinet FortiSandbox is vulnerable to a critical (9.8) unauthenticated OS command injection. Patch immediately to prevent remote code execution.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| fortisandbox | 4.2.0 | 4.2.8 | vulnerable |
| fortisandbox | 4.4.0 | 4.4.9 | vulnerable |
| fortisandbox | 5.0.0 | 5.0.6 | vulnerable |
| fortisandbox_cloud | 5.0.4 | 5.0.6 | vulnerable |
| fortisandbox_paas | 5.0.4 | 5.0.6 | vulnerable |
Consult Fortinet's PSIRT advisory (FG-IR-26-141) and apply the recommended firmware updates for your specific FortiSandbox model and deployment type, including Physical, Cloud, and PaaS versions.
Upgrade FortiSandbox to version 5.0.6, 4.4.9, or higher. For users on the 4.2 branch, migrate to a supported, patched version as all 4.2 versions are identified as vulnerable.
Limit network access to the FortiSandbox management interface to trusted internal IP addresses only. Use a firewall or VPN to ensure the appliance is not exposed to the public internet.
Conduct forensic triage of FortiSandbox logs in accordance with CISA's BOD 26-04 guidance. Look for suspicious HTTP requests containing shell metacharacters or unauthorized system-level configuration changes.
Security teams should inspect HTTP access logs for FortiSandbox management interfaces, looking for suspicious characters associated with OS command injection (e.g., ';', '|', '&', '$()') within request parameters. Monitor for unusual outbound network connections originating from the FortiSandbox appliance itself, which may indicate a reverse shell. Additionally, check system integrity logs for unauthorized administrative users or unexpected process execution outside of normal sandbox operations.
Experience superior visibility and a simpler approach to cyber risk management