Fortinet Security Update – 18 June 2023

Fortinet has released a security update to fix several vulnerabilities in multiple versions of FortiOS and FortiProxy.

The addressed vulnerabilities could allow the attacker to cause a denial of service attack by sending a specially crafted request to the affected products.

Sample of the addressed vulnerabilities:

Fortinet FortiOS and FortiProxy Denial of Service (CVE-2023-33306):

  • CVSS: 6.4
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Denial of Service

Affected products:

  • FortiOS version 7.2.0 through 7.2.4.
  • FortiOS version 7.0.0 through 7.0.10.
  • FortiProxy version 7.2.0 through 7.2.2.
  • FortiProxy version 7.0.0 through 7.0.8.
Vulnerabilities
  • CVE-2023-33306
  • CVE-2023-33307
Mitigations

The enterprise should deploy the patch as soon as the testing phase is completed.

Fortinet Security Advisory

References