CVE-2024-54027: Fortinet FortiSandbox

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.

Affected products

  • Fortinet FortiSandbox: from 3.0.5, before 4.0.6 (fixed in 4.0.6); from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.4.0, before 4.4.7 (fixed in 4.4.7); version 5.0.0 only

Published 2025-03-17. Last modified 2026-06-17.