Rewterz Threat Advisory – Multiple Fortinet FortiOS, FortiProxy and Fortiweb Vulnerabilities
June 13, 2023Rewterz Threat Advisory – Multiple Fortinet FortiNAC Vulnerabilities
June 13, 2023Rewterz Threat Advisory – Multiple Fortinet FortiOS, FortiProxy and Fortiweb Vulnerabilities
June 13, 2023Rewterz Threat Advisory – Multiple Fortinet FortiNAC Vulnerabilities
June 13, 2023Severity
High
Analysis Summary
CVE-2023-26210 CVSS:7.8
Fortinet FortiADC and FortiADC Manager could allow a local authenticated attacker to execute arbitrary code on the system, caused by an OS command injection flaw. By sending specially crafted CLI requests, an attacker could exploit this vulnerability to execute arbitrary shell code as root user.
CVE-2023-28000 CVSS:6.7
Fortinet FortiADC could allow a local authenticated attacker to execute arbitrary commands on the system, caused by an OS command injection flaw in the CLI. By sending specially crafted arguments in diagnose system df CLI command, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Impact
- Code Execution
- Command Execution
Indicators Of Compromise
CVE
- CVE-2023-26210
- CVE-2023-28000
Affected Vendors
Fortinet
Affected Products
- Fortinet FortiADCManager 5.3.0
- Fortinet FortiADC 7.0.0
- Fortinet FortiADC 6.1
- Fortinet FortiADC 6.0
- Fortinet FortiADC 5.4
- Fortinet FortiADC 5.3
- Fortinet FortiADC 5.2
- Fortinet FortiADC 7.1.0
- Fortinet FortiADC 7.1.2
- Fortinet FortiADC 6.2.0
- Fortinet FortiADCManager 5.2
- Fortinet FortiADCManager 5.4
- Fortinet FortiADCManager 6.0
- Fortinet FortiADCManager 6.1
- Fortinet FortiADCManager 6.2
- Fortinet FortiADCManager 7.0.0
- Fortinet FortiADCManager 7.1.0
Remediation
Upgrade to the latest version of FortiOS, available from the Fortinet Web site.