CVE Vulnerabilities

CVE-2024-54027

Use of Hard-coded Cryptographic Key

Published: Mar 17, 2025 | Modified: Jul 24, 2025
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.

Weakness

The product uses a hard-coded, unchangeable cryptographic key.

Affected Software

NameVendorStart VersionEnd Version
FortisandboxFortinet3.0.5 (including)4.0.6 (excluding)
FortisandboxFortinet4.2.0 (including)4.2.8 (excluding)
FortisandboxFortinet4.4.0 (including)4.4.7 (excluding)
FortisandboxFortinet5.0.0 (including)5.0.0 (including)

Potential Mitigations

References