7.2
CVE-2026-84387
- EPSS 0.88%
- Veröffentlicht 08.09.2026 16:41:43
- Zuletzt bearbeitet 08.09.2026 18:35:10
- Erkennungen
A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFortinet
≫
Produkt
FortiSandbox
Default Statusunaffected
Version
5.2.0
Status
affected
Version <=
5.0.6
Version
5.0.0
Status
affected
Version <=
4.4.9
Version
4.4.0
Status
affected
Version <=
4.2.8
Version
4.2.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.88% | 0.569 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Fortinet | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
https://fortiguard.fortinet.com/psirt/FG-IR-26-167