Skip to main content

Critical Security Updates for FortiNAC and FortiWeb

Fortinet has released security updates to address 2 Critical, 15 High, and 22 Medium impact vulnerabilities in FortiNAC, FortiWeb, FortiOS, and other Fortinet products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Fortinet has released security updates to address 2 Critical, 15 High, and 22 Medium impact vulnerabilities in FortiNAC, FortiWeb, FortiOS, and other Fortinet products


The following platforms are also known to be affected:

  • FortiAnalyzer
  • FortiSandbox
  • FortiWAN
  • FortiAuthenticator
  • FortiExtender
  • FortiSwitchManager

Threat details

Introduction

Fortinet has released security updates to address 2 Critical, 15 High, and 22 Medium impact vulnerabilities in FortiNAC, FortiWeb, FortiOS, and other Fortinet products. The 2 Critical vulnerabilities are CVE-2022-39952 affecting FortiNAC and CVE-2021-42756 affecting FortiWeb. 

The external control of file name or path vulnerability in FortiNAC webserver, known as CVE-2022-39952, has a CVSSv3 score of 9.8 and could allow an unauthenticated attacker to perform arbitrary write on the system. 

The multiple stack-based buffer overflow vulnerability in FortiWeb's proxy daemon, known as CVE-2021-42756, has a CVSSv3 score of 9.8 and could allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.

Exploitation in the wild for CVE-2022-39952 and CVE-2023-21756

A proof-of-concept (PoC) for CVE-2022-39952, a Critical vulnerability in FortiNAC, has been publicly released. This vulnerability is being exploited.

A PoC has also been publicly released for CVE-2023-21756, a buffer overflow vulnerability that could lead to arbitrary code execution. This vulnerability is also being exploited.


Threat updates

Date Update
28 Feb 2023 Exploitation of CVE-2023-21756

This article has been updated to reflect this change. 

23 Feb 2023 Proof-of-concept released for CVE-2022-39952

This article has been updated to reflect this change. 


Remediation advice

Affected organisations are encouraged to review Fortinet's Product Security Incident Response Team's PSIRT Advisories page and apply any relevant updates.


Remediation steps

Type Step
Patch

FortiNAC - External Control of File Name or Path in keyUpload scriptlet | FG-IR-22-300


https://www.fortiguard.com/psirt/FG-IR-22-300
Patch

FortiWeb - Stack-based buffer overflows in Proxyd | FG-IR-21-186


https://www.fortiguard.com/psirt/FG-IR-21-186
Patch

FortiADC - OS command injection vulnerability in CLI | FG-IR-22-046


https://www.fortiguard.com/psirt/FG-IR-22-046
Patch

FortiExtender - multiple command injection vulnerabilities in webserver | FG-IR-22-048


https://www.fortiguard.com/psirt/FG-IR-22-048
Patch

FortiNAC - Multiple Command Injections in webserver | FG-IR-22-280


https://www.fortiguard.com/psirt/FG-IR-22-280
Patch

FortiNAC - Unauthenticated access to administrative operations | FG-IR-22-329


https://www.fortiguard.com/psirt/FG-IR-22-329
Patch

FortiNAC - Weak password storage | FG-IR-22-265


https://www.fortiguard.com/psirt/FG-IR-22-265
Patch

FortiOS -- XSS vulnerability in the Login page when FortiCloud Sign-in is used | FG-IR-22-224


https://www.fortiguard.com/psirt/FG-IR-22-224
Patch

FortiOS, FortiProxy & FortiSwitchManager - Arbitrary read/write vulnerability in administrative interface | FG-IR-22-391


https://www.fortiguard.com/psirt/FG-IR-22-391
Patch

FortiWAN - Command injection vulnerability | FG-IR-22-157


https://www.fortiguard.com/psirt/FG-IR-22-157
Patch

FortiWeb - Command injection in CLI backup functionality | FG-IR-22-131


https://www.fortiguard.com/psirt/FG-IR-22-131
Patch

FortiWeb - Double free in pipe management | FG-IR-22-348


https://www.fortiguard.com/psirt/FG-IR-22-348
Patch

FortiWeb - Heap based overflow in CLI | FG-IR-22-111


https://www.fortiguard.com/psirt/FG-IR-22-111
Patch

FortiWeb - Multiple Stack based buffer overflow in web interface | FG-IR-22-118


https://www.fortiguard.com/psirt/FG-IR-22-118
Patch

FortiWeb - OS command injection in Web GUI | FG-IR-22-163


https://www.fortiguard.com/psirt/FG-IR-22-163
Patch

FortiWeb - Stack-based Buffer Overflow in command line interpreter | FG-IR-21-234


https://www.fortiguard.com/psirt/FG-IR-21-234
Patch

FortiWeb - Weak generation of WAF session IDs leads to session fixation | FG-IR-21-214


https://www.fortiguard.com/psirt/FG-IR-21-214

Definitive source of threat updates


Last edited: 28 February 2023 2:26 pm