Skip to main content

Fortinet Releases Security Updates for Multiple Products

Updates address 1 Critical, 9 High, and 10 Medium severity vulnerabilities in FortiPresence, FortiOS, FortiWeb, and other Fortinet products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Updates address 1 Critical, 9 High, and 10 Medium severity vulnerabilities in FortiPresence, FortiOS, FortiWeb, and other Fortinet products


The following platforms are also known to be affected:

  • FortiClientWindows
  • FortiAnalyzer
  • FortiSandbox
  • FortiAuthenticator
  • FortiManager
  • FortiNAC
  • FortiSIEM
  • FortiDDoS
  • FortiDDoS-F
  • FortiClientMac
  • FortiSOAR
  • FortiDeceptor

Threat details

Introduction

Fortinet has released security updates to address 1 Critical, 9 High, and 10 Medium severity vulnerabilities in FortiPresence, FortiOS, FortiWeb, and other Fortinet products. The Critical severity vulnerability, known as CVE-2022-41331, is an improper access control vulnerability for FortiPresence. A remote, unauthenticated attacker could exploit this vulnerability with crafted authentication requests to gain access to the Redis and MongoDB instances. 


Remediation advice

Affected organisations are encouraged to review Fortinet's Security Advisory and apply the relevant updates.


Remediation steps

Type Step
Patch

FortiPresence - Unpassworded remotely accessible Redis & MongoDB | FG-IR-22-355


https://www.fortiguard.com/psirt/FG-IR-22-355
Patch

CVE-2022-0847 on Linux Kernel | FG-IR-22-050


https://www.fortiguard.com/psirt/FG-IR-22-050
Patch

FortiADC & FortiDDoS & FortiDDoS-F - Command injection in log & report module | FG-IR-22-335


https://www.fortiguard.com/psirt/FG-IR-22-335
Patch

FortiClient (Windows) - Arbitrary file creation from unprivileged users due to process impersonation | FG-IR-22-336


https://www.fortiguard.com/psirt/FG-IR-22-336
Patch

FortiClient (Windows) - Improper write access over FortiClient pipe object | FG-IR-22-429


https://www.fortiguard.com/psirt/FG-IR-22-429
Patch

FortiClientWindows - Arbitrary file creation by unprivileged users | FG-IR-22-320


https://www.fortiguard.com/psirt/FG-IR-22-320
Patch

FortiOS & FortiProxy - Cross Site Scripting vulnerabilities in administrative interface | FG-IR-22-363


https://www.fortiguard.com/psirt/FG-IR-22-363
Patch

FortiSOAR - Server-side Template Injection in playbook execution | FG-IR-23-051


https://www.fortiguard.com/psirt/FG-IR-23-051
Patch

FortiSandbox / FortiDeceptor - Improper profile-based access control over APIs | FG-IR-22-056


https://www.fortiguard.com/psirt/FG-IR-22-056
Patch

FortiWeb - XSS vulnerability in HTML generated attack report files | FG-IR-22-428


https://www.fortiguard.com/psirt/FG-IR-22-428

Definitive source of threat updates


CVE Vulnerabilities

Last edited: 12 April 2023 2:38 pm