FORTINET Security Advisory
Published Date: Not specified
Advisory Summary
🚨 ALERT Cron Job Injection in Remote Backup (FortiSandbox)
- CVSS v3: 6.7 (moderate—potentially high impact due to privileged execution)
- tampering with backup schedules or execution outcomes
- persistence via job manipulation
- escalation of impact depending on integration with broader SOC/automation tooling
- FortiSandbox (PSIRT advisory indicates a specific issue in handling remote backup / cron job behavior)
- restrict access to FortiSandbox management/backup surfaces (IP allowlists, VPN-only)
- deploy WAF/IPS signatures where available for command injection patterns
- log and alert on anomalous request parameters around backup scheduling/execution
- Likelihood: depends on exposure (internet-reachable services and presence of privileged foothold)
- Impact: potentially meaningful due to unauthorized command execution under privileged context
Reference: Vendor Advisory