CVE Vulnerabilities

CVE-2024-54027

Use of Hard-coded Cryptographic Key

Published: Mar 17, 2025 | Modified: Jul 24, 2025
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.

Weakness

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.

Affected Software

Name Vendor Start Version End Version
Fortisandbox Fortinet 3.0.5 (including) 4.0.6 (excluding)
Fortisandbox Fortinet 4.2.0 (including) 4.2.8 (excluding)
Fortisandbox Fortinet 4.4.0 (including) 4.4.7 (excluding)
Fortisandbox Fortinet 5.0.0 (including) 5.0.0 (including)

Potential Mitigations

References