A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortisandbox | 3.2.0 | 3.2.3 |
| fortinet / fortisandbox | 3.1.0 | 3.1.4.x |
| fortinet / fortisandbox | 4.0.0 | 4.0.0.x |