Wednesday, March 22, 2023
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory
  • Login
  • Register
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7 News
No Result
View All Result

Home > Cybersecurity > Fortinet releases patches for multiple vulnerabilities

Fortinet releases patches for multiple vulnerabilities

Fortinet releases patches for 40 vulnerabilities including two of them which were rated CVSSv3 Score 9.3 and CVSSv3 Score 9.8 as critical vulnerabilities.


Ezgi Koc Ezgi Koc
February 20, 2023
3 min read
Fortinet releases patches for multiple vulnerabilities
  • Fortinet addressed and published patches for 40 vulnerabilities found in multiple solutions on February 16, 2023.
  • These 40 vulnerabilities include 2 of them which were rated CVSSv3 Score 9.3 and CVSSv3 Score 9.8 as critical vulnerabilities.
  • The recommended solution to these vulnerabilities is to update the software to the latest version as usual.

Fortinet is a multinational firm based in the United States. Physical firewalls, antivirus software, intrusion prevention systems, and endpoint security components are among the cybersecurity solutions developed and sold by the company. On February 16, 2023, Fortinet addressed and released patches for multiple vulnerabilities.

Table of Contents

  • FortiADC – OS command injection vulnerability in CLI (CVSSv3 Score 7.4)
    • Affected Products
    • Solutions
  • FortiExtender – multiple command injection vulnerabilities in webserver (CVSSv3 Score 7.2)
    • Affected Products
    • Solutions
  • FortiWeb – Stack-based buffer overflows in Proxyd (CVSSv3 Score 9.3)
    • Affected Products
    • Solutions
  • FortiNAC – External Control of File Name or Path in keyUpload scriptlet (CVSSv3 Score 9.8)
    • Affected Products
    • Solutions

FortiADC – OS command injection vulnerability in CLI (CVSSv3 Score 7.4)

A FortiADC vulnerability (CWE-78) that allows an authorized attacker to execute arbitrary shell code as ‘root’ via CLI commands due to improper neutralization of special elements used in an OS command (‘OS Command Injection’). It is tracked as CVE-2022-27482.

Affected Products

FortiADC version 7.0.0 through 7.0.1
FortiADC version 6.2.0 through 6.2.3
FortiADC 6.1 all versions
FortiADC 6.0 all versions
FortiADC 5.4 all versions
FortiADC 5.3 all versions
FortiADC 5.2 all versions
FortiADC 5.1 all versions
FortiADC 5.0 all versions

Solutions

Upgrade to FortiADC version 7.0.2 or above,

Upgrade to FortiADC version 6.2.4 or above.

FortiExtender – multiple command injection vulnerabilities in webserver (CVSSv3 Score 7.2)

A privileged attacker may be able to execute arbitrary OS commands in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.2.4 via carefully constructed input parameters due to poor neutralization of special elements used in an OS command vulnerability in FortiExtender’s web server. It is tracked as CVE-2022-27489.

Affected Products

FortiExtender version 7.0.0 through 7.0.3
FortiExtender version 4.2.0 through 4.2.4
FortiExtender version 4.1.1 through 4.1.8
FortiExtender version 4.0.0 through 4.0.2
FortiExtender version 3.3.0 through 3.3.2
FortiExtender version 3.2.1 through 3.2.3
FortiExtender 5.3 all versions
FortiExtender 3.1 all versions
FortiExtender 3.0 all versions

Solutions

Upgrade to FortiExtender version 7.2.0 and above
Upgrade to FortiExtender version 7.0.4 and above
Upgrade to FortiExtender upcoming version 4.2.5 and above
Upgrade to FortiExtender upcoming version 4.1.9 and above
Upgrade to FortiExtender upcoming version 4.0.3 and above
Upgrade to FortiExtender version 3.3.3 and above
Upgrade to FortiExtender version 3.2.4 and above

FortiWeb – Stack-based buffer overflows in Proxyd (CVSSv3 Score 9.3)

Certain stack-based buffer overflow vulnerabilities in FortiWeb’s proxy daemon could allow an unauthenticated remote attacker to execute arbitrary code via specially crafted HTTP requests. It is tracked as CVE-2021-42756.

Affected Products

FortiWeb versions 5.x all versions,
FortiWeb versions 6.0.7 and below,
FortiWeb versions 6.1.2 and below,
FortiWeb versions 6.2.6 and below,
FortiWeb versions 6.3.16 and below,
FortiWeb versions 6.4 all versions.

Solutions

Upgrade to FortiWeb 7.0.0 or above,
Upgrade to FortiWeb 6.3.17 or above,
Upgrade to FortiWeb 6.2.7 or above.
Upgrade to FortiWeb 6.1.3 or above.
Upgrade to FortiWeb 6.0.8 or above.

FortiNAC – External Control of File Name or Path in keyUpload scriptlet (CVSSv3 Score 9.8)

An unauthenticated attacker may be able to perform arbitrary write on the system due to an external control of file name or path vulnerability in the FortiNAC webserver. It is tracked as CVE-2022-39952.

Affected Products

FortiNAC version 9.4.0
FortiNAC version 9.2.0 through 9.2.5
FortiNAC version 9.1.0 through 9.1.7
FortiNAC 8.8 all versions
FortiNAC 8.7 all versions
FortiNAC 8.6 all versions
FortiNAC 8.5 all versions
FortiNAC 8.3 all versions

Solutions

Please upgrade to FortiNAC version 9.4.1 or above
Please upgrade to FortiNAC version 9.2.6 or above
Please upgrade to FortiNAC version 9.1.8 or above
Please upgrade to FortiNAC version 7.2.0 or above

If you would like to check out the rest of the vulnerabilities reported by Fortinet, click here.

See more Cybersecurity News

A comprehensive guide to understanding Cybersecurity: What is Cybersecurity?


Tags: Fortinet
Ezgi Koc

Ezgi Koc

Ezgi Koc is an editor at Cloud7. She graduated from Ege University with a bachelor's degree in English Language and Literature. She has always had great interest in technology, both hardware and software, since her childhood and decided to pursue a career that would enable her to broaden her horizons in this field. She is very passionate about video games as a Twitch affiliate and streams games in her free time.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Next Post
Stolen Atlassian data leaked online

Stolen Atlassian data leaked online

Related News

7 best cybersecurity schools

7 best cyber security schools

March 21, 2023 9:00 pm
Akamai researchers warn about the new HinataBot botnet

Akamai researchers warn about the new HinataBot botnet

March 20, 2023 6:10 pm
7 biggest data breaches in the history of the internet

7 biggest data breaches in the history of the internet

March 16, 2023 10:55 pm
The number of ransomware attacks increased by 82% in 2022

The number of ransomware attacks increased by 82% in 2022

March 14, 2023 6:45 pm
Get free daily newsletters from Cloud7 News Get the Cloud7 Newsletter
Select list(s):

Check your inbox or spam folder to confirm your subscription.

By subscribing, you agree to our
Copyright Policy and Privacy Policy

Get the free newsletter

Subscribe to receive the latest IT business updates straight to your inbox.

Select list(s):

Check your inbox or spam folder to confirm your subscription.

Recent News

  • 7 best cyber security schools
  • 7 oldest Linux distros that are still being maintained
  • OVHcloud purchases its first Quandela quantum computer
  • Leil Storage launches an innovative data storage solution
  • Tails 5.11 is released, download it now

Cloud7 News
Cloud7 is a news source that publishes the latest news, reviews, comparisons, opinions, and exclusive interviews to help tech users of high-experience levels in the IT industry.

EXPLORE

  • Web Hosting
  • Cloud Computing
  • Data Center
  • Cybersecurity
  • Linux
  • Network/Internet
  • Software
  • Hardware
  • Artificial Intelligence
  • How-Tos
  • Troubleshooting

RESOURCES

  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

Get the Cloud7 Newsletter

Get FREE daily newsletters from Cloud7 delivering the latest news and reviews.

  • About Us
  • Privacy & Policy
  • Copyright Policy
  • Contact

© 2023, Cloud7 News. All rights reserved.

No Result
View All Result
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

© 2023, Cloud7 News. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.