Readonly user could execute sensitive operations

Summary

A client-side enforcement of server-side security vulnerability [CWE-602] in FortiSandbox may allow an authenticated attacker with at least read-only permission to download or upload configuration.

Version Affected Solution
FortiSandbox 4.4 4.4.0 through 4.4.4 Upgrade to 4.4.5 or above
FortiSandbox 4.2 4.2.1 through 4.2.6 Upgrade to 4.2.7 or above
FortiSandbox 4.0 Not affected Not Applicable
FortiSandbox 3.2 Not affected Not Applicable

Fortinet in Q3/24 has remediated this issue in FortiSandbox Cloud version 24.1 and hence the customers need not perform any action.

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2024-05-14: Initial publication
2025-05-07: Clarify fix information for FortiSandbox Cloud product