Fortinet Alert
2792Warning Date
Severity Level
Warning Number
Target Sector
2 February, 2022
● High
2022-4316
All
Fortinet has released security updates to address several vulnerabilities in the following products:
- FortiWeb
- 6.4.1 and below
- 6.3.15 and below
- 6.2.x
- 6.1.x
- 6.0.x
- 5.9.x
- 5.8.x.
- FortiMail
- 7.0.1 and below
- 6.4.5 and below
- 6.2.7 and below
- FortiExtender
- 7.0.1 and below
- 4.2.3 and below
- 4.1.7 and below
- FortiAuthenticator
- 6.3.2 and below
- 6.2.x.
- 6.1.x.
- 6.0.x.
An attacker could exploit these vulnerabilities by doing the following:
- Privilege escalation
- Cross-site scripting (XSS) attack
- Make an unauthenticated direct connection to the FAC's database
- Arbitrary code exaction
The CERT team encourages users to review Fortinet security advisory and apply the necessary updates:
- https://www.fortiguard.com/psirt/FG-IR-21-158
- https://www.fortiguard.com/psirt/FG-IR-21-132
- https://www.fortiguard.com/psirt/FG-IR-21-166
- https://www.fortiguard.com/psirt/FG-IR-21-180
- https://www.fortiguard.com/psirt/FG-IR-21-185
- https://www.fortiguard.com/psirt/FG-IR-21-148
- https://www.fortiguard.com/psirt/FG-IR-20-217