CVE-2021-22125 is a vulnerability in Fortinet Fortisandbox
Published on July 20, 2021
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file.
Vulnerability Analysis
Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
LOW
Products Associated with CVE-2021-22125
Want to know whenever a new CVE is published for Fortinet Fortisandbox? stack.watch will email you.
Affected Versions
Fortinet FortiSandbox Version FortiSandbox before 3.2.2 is affected by CVE-2021-22125Exploit Probability
EPSS
0.31%
Percentile
53.41%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.