CVE-2021-22125
CVE-2021-22125
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 1.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Jul 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Affected products
Fortinet · Fortinet FortiSandboxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →