Fortinet Addresses Security Flaws in FortiOS and Additional Products

Fortinet, a prominent name in cybersecurity, has announced the release of critical patches for multiple vulnerabilities impacting its FortiOS, FortiProxy, FortiPAM, FortiSwitchManager, FortiManager, and FortiAnalyzer solutions.

These vulnerabilities could potentially allow unauthorized access and escalate privileges, posing serious risks to affected systems.

Vulnerability Overview

CVE-2022-45862

An issue with session expiration in the graphical user interfaces (GUIs) of FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager has been identified. This flaw (CWE-613) allows attackers to potentially reuse sessions after a user has logged out, assuming they have valid credentials.

  • Severity: Medium (CVSSv3 score of 3.5)
  • Affected Products and Fixes:
  • FortiOS: Versions 7.2.0 through 7.2.5 are impacted. Upgrade to 7.2.6 or higher. All versions of 7.0 and 6.4 are also affected and need upgrading to a patched release.
  • FortiPAM: Versions 1.0 to 1.3 are affected. Upgrade to a fixed release.
  • FortiProxy: All 7.2 and 7.0 versions are impacted. Upgrade to a patched release.
  • FortiSwitchManager: Versions 7.2.0 through 7.2.1 are affected. Upgrade to 7.2.2 or higher.

CVE-2024-21757

A vulnerability in FortiManager and FortiAnalyzer (CWE-620) allows users with read-write access to alter admin passwords through device configuration backups, which could lead to privilege escalation.

  • Severity: Medium (CVSSv3 score of 5.5)
  • Affected Products and Fixes:
  • FortiAnalyzer: Versions 7.4.0 through 7.4.1 should be upgraded to 7.4.2 or higher. Versions 7.2.0 through 7.2.4 should be upgraded to 7.2.5 or above.
  • FortiManager: Versions 7.4.0 through 7.4.1 need upgrading to 7.4.2 or higher. Versions 7.2.0 through 7.2.4 should be upgraded to 7.2.5 or higher.

CVE-2024-36505

An issue with access control (CWE-284) in FortiOS permits an attacker with write access to bypass the file integrity checking system.

  • Severity: Medium (CVSSv3 score of 4.7)
  • Affected Products and Fixes:
  • FortiOS: Versions 7.4.0 through 7.4.3 should be upgraded to 7.4.4 or higher. Versions 7.2.5 through 7.2.7 should be upgraded to 7.2.8 or higher. Versions 7.0.12 through 7.0.14 should be upgraded to 7.0.15 or above.

Fortinet has yet to report any instances of these vulnerabilities being exploited in the wild.

Users and administrators are strongly advised to apply the provided patches to ensure their systems are secure and to mitigate the risks posed by these vulnerabilities.

More Articles & Posts