Fortinet Releases Security Updates for Multiple Products
Updates address 1 Critical, 9 High, and 10 Medium severity vulnerabilities in FortiPresence, FortiOS, FortiWeb, and other Fortinet products
Summary
Updates address 1 Critical, 9 High, and 10 Medium severity vulnerabilities in FortiPresence, FortiOS, FortiWeb, and other Fortinet products
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
- FortiClientWindows
- FortiAnalyzer
- FortiSandbox
- FortiAuthenticator
- FortiManager
- FortiNAC
- FortiSIEM
- FortiDDoS
- FortiDDoS-F
- FortiClientMac
- FortiSOAR
- FortiDeceptor
Threat details
Introduction
Fortinet has released security updates to address 1 Critical, 9 High, and 10 Medium severity vulnerabilities in FortiPresence, FortiOS, FortiWeb, and other Fortinet products. The Critical severity vulnerability, known as CVE-2022-41331, is an improper access control vulnerability for FortiPresence. A remote, unauthenticated attacker could exploit this vulnerability with crafted authentication requests to gain access to the Redis and MongoDB instances.
Remediation advice
Affected organisations are encouraged to review Fortinet's Security Advisory and apply the relevant updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
FortiPresence - Unpassworded remotely accessible Redis & MongoDB | FG-IR-22-355 https://www.fortiguard.com/psirt/FG-IR-22-355 |
| Patch |
CVE-2022-0847 on Linux Kernel | FG-IR-22-050 https://www.fortiguard.com/psirt/FG-IR-22-050 |
| Patch |
FortiADC & FortiDDoS & FortiDDoS-F - Command injection in log & report module | FG-IR-22-335 https://www.fortiguard.com/psirt/FG-IR-22-335 |
| Patch |
FortiClient (Windows) - Arbitrary file creation from unprivileged users due to process impersonation | FG-IR-22-336 https://www.fortiguard.com/psirt/FG-IR-22-336 |
| Patch |
FortiClient (Windows) - Improper write access over FortiClient pipe object | FG-IR-22-429 https://www.fortiguard.com/psirt/FG-IR-22-429 |
| Patch |
FortiClientWindows - Arbitrary file creation by unprivileged users | FG-IR-22-320 https://www.fortiguard.com/psirt/FG-IR-22-320 |
| Patch |
FortiOS & FortiProxy - Cross Site Scripting vulnerabilities in administrative interface | FG-IR-22-363 https://www.fortiguard.com/psirt/FG-IR-22-363 |
| Patch |
FortiSOAR - Server-side Template Injection in playbook execution | FG-IR-23-051 https://www.fortiguard.com/psirt/FG-IR-23-051 |
| Patch |
FortiSandbox / FortiDeceptor - Improper profile-based access control over APIs | FG-IR-22-056 https://www.fortiguard.com/psirt/FG-IR-22-056 |
| Patch |
FortiWeb - XSS vulnerability in HTML generated attack report files | FG-IR-22-428 https://www.fortiguard.com/psirt/FG-IR-22-428 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 12 April 2023 2:38 pm