Fortinet Security Updates – 18 September 2023

Fortinet has released security updates to fix several vulnerabilities across multiple products.

The addressed vulnerabilities could allow the attacker to gain access, obtain sensitive information, or manipulate files on the affected products.

Sample of the addressed vulnerabilities:

1- Fortinet FortiWeb Code Execution Vulnerability (CVE-2023-34984):

  • CVSS: 7.1
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2- Fortinet FortiAP-U File Deletion Vulnerability (CVE-2023-36634):

  • CVSS: 6.5
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: File Manipulation

Sample of the affected products:

  • FortiWeb version 6.3.6 through 7.2.1.
  • FortiTester version 2.3 through 4.2 and 7.0 through 7.2.
Vulnerabilities
  • CVE-2023-25608
  • CVE-2023-36634
  • CVE-2021-44172
  • CVE-2023-36638
  • CVE-2023-27998
  • CVE-2023-36551
  • CVE-2023-36642
  • CVE-2023-40715
  • CVE-2023-40717
  • CVE-2023-34984
Mitigations

The enterprise should deploy these patches as soon as the testing phase is completed.

Fortinet Security Advisory

References