Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Medium
CVE-2023-33305 CVSS:4.9
Fortinet FortiOS, FortiProxy and Fortiweb is vulnerable to a denial of service, caused by an infinite loop flaw. By using a specially crafted firmware image a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2023-41327 CVSS:7.8
Fortinet FortiOS and FortiProxy could allow a local authenticated attacker to obtain sensitive information, caused by the transmission of sensitive information in plain text. By using the diagnose CLI commands to intercept traffic, an attacker could exploit this vulnerability to obtain administrators cookies, and use this information to launch further attacks against the affected system.
CVE-2023-29178 CVSS:4.3
Fortinet FortiOS and FortiProxy are vulnerable to a denial of service, caused by an access of uninitialized pointer flaw in the administrative interface API. By sending specially crafted HTTP or HTTPS requests, a remote authenticated attacker could exploit this vulnerability to cause the httpsd process to crash.
CVE-2023-43953 CVSS:6.7
Fortinet FortiOS and FortiProxy could allow a local authenticated attacker to execute arbitrary code on the system, caused by a format string flaw in the command line interpreter. By sending specially crafted command arguments, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVE-2023-29175 CVSS:4.8
Fortinet FortiOS and FortiProxy is vulnerable to a man-in-the-middle attack, caused by the lack of certificate verification when establishing secure connections with FortiGuard’s map server. An attacker could exploit this vulnerability to launch a man-in-the-middle attack and gain access to the communication channel between endpoints to obtain sensitive information or further compromise the system.
CVE-2023-22639 CVSS:6.7
Fortinet FortiOS and FortiProxy could allow a local authenticated attacker to execute arbitrary code on the system, caused by an out-of-bounds write flaw in the Command Line Interface. By sending specially crafted commands, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Fortinet
Refer to FortiGuard Advisory for patch, upgrade or suggested workaround information.