← Back

CVE-2024-54027

nvd nist
Published: Mar 17, 2025Modified: Jul 24, 2025

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.8 / Impact: 3.6
Source: NVD

Description

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.

Affected (4)

1 product
Fortisandbox
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 3.0.5 to 4.0.6
From 4.2.0 to 4.2.8
From 4.4.0 to 4.4.7
Version 5.0.0

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.