Skip to main content

Fortinet Release Multiple Security Updates

Updates address 1 Low, 8 Medium, and 5 High severity vulnerabilities including an actively exploit vulnerability in FortiOS

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Updates address 1 Low, 8 Medium, and 5 High severity vulnerabilities including an actively exploit vulnerability in FortiOS


Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

  • FortiAnalyzer
  • FortiAuthenticator
  • FortiDeceptor
  • FortiMail
  • FortiPortal
  • FortiSwitch
  • FortiSOAR
  • FortiRecorder

Threat details

Introduction

Fortinet has released security updates to address 1 Low, 8 Medium, and 5 High severity vulnerabilities in FortiNAC, FortiWeb, FortiOS, and other Fortinet products. The High severity vulnerabilities include CVE-2022-40676 - a cross-site scripting (XSS) vulnerability in FortiNAC, CVE-2022-39953 - an improper privilege management vulnerability in FortiNAC, CVE-2022-25605 - an improper access control vulnerability in FortiSOAR, CVE-2022-42476 - a relative path traversal vulnerability in FortiOS and FortiProxy, and CVE-2022-39951 - an improper neutralisation of special elements in an OS command vulnerability in FortiWeb.

Exploitation in the wild for CVE-2022-41328

CVE-2022-41328 is a path traversal vulnerability affecting FortiOS has been reported to be actively exploited. The vulnerability could allow an authenticated remote attacker to execute arbitrary code or commands.


Threat updates

Date Update
14 Mar 2023 Exploitation in the wild for CVE-2022-41328

This Cyber alert has been updated to reflect the change in exploitation status of CVE-2022-41328 and has been upgraded to Medium severity.


Remediation advice

Affected organisations are encouraged to review Fortinet's Security Advisory and apply the relevant updates.


Remediation steps

Type Step
Patch

FortiAnalyzer - CSV injection in macro name | FG-IR-22-488


https://www.fortiguard.com/psirt/FG-IR-22-488
Patch

FortiAnalyzer -- the log-fetch client request password is shown in clear text in the heartbeat response | FG-IR-22-447


https://www.fortiguard.com/psirt/FG-IR-22-447
Patch

FortiAuthenticator, FortiDeceptor & FortiMail - Improper restriction over excessive authentication attempts
| FG-IR-20-078


https://www.fortiguard.com/psirt/FG-IR-20-078
Patch

FortiManager, FortiAnalyzer, FortiPortal & FortiSwitch - Information disclosure through diagnose debug commands | FG-IR-18-232


https://www.fortiguard.com/psirt/FG-IR-18-232
Patch

FortiNAC - Multiple privilege escalation via sudo command | FG-IR-22-309


https://www.fortiguard.com/psirt/FG-IR-22-309
Patch

FortiOS & FortiProxy - Access of NULL pointer in SSLVPNd | FG-IR-22-477


https://www.fortiguard.com/psirt/FG-IR-22-477
Patch

FortiOS - Path traversal in execute command | FG-IR-22-369


https://www.fortiguard.com/psirt/FG-IR-22-369
Patch

FortiOS / FortiProxy - Path traversal vulnerability allows VDOM escaping | FG-IR-22-401


https://www.fortiguard.com/psirt/FG-IR-22-401
Patch

FortiOS / FortiProxy - Unauthenticated access to static files containing logging information | FG-IR-22-364


https://www.fortiguard.com/psirt/FG-IR-22-364
Patch

FortiRecorder - DoS in login authentication mechanism | FG-IR-22-388


https://www.fortiguard.com/psirt/FG-IR-22-388
Patch

FortiSOAR - Improper Authorization in request headers | FG-IR-23-050


https://www.fortiguard.com/psirt/FG-IR-23-050
Patch

FortiWeb - command injection in webserver | FG-IR-22-254


https://www.fortiguard.com/psirt/FG-IR-22-254
Patch

FortiWeb and FortiRecorder - Arbitrary file read through command line pipe | FG-IR-21-218


https://www.fortiguard.com/psirt/FG-IR-21-218

Definitive source of threat updates


CVE Vulnerabilities

Last edited: 14 March 2023 12:13 pm