Fortinet Alert
2484Warning Date
Severity Level
Warning Number
Target Sector
4 May, 2022
● High
2022-4773
All
Fortinet has released security updates to address several vulnerabilities in the following products:
- FortiFone
- 3.0.11 and below
- FortiSOAR
- 7.0.2 and below
- 6.4.4 and below
- 6.0.0
- 5.x.x
- FortiOS
- 7.0.3 and below
- 6.4.8 and below
- 6.2.10 and below
- 6.0.14 to 6.0.0
- 6.2.0 - 6.2.10
- 6.4.0 - 6.4.8
- 7.0.0
- FortiProxy
- 7.0.1 and below
- 2.0.7 - 2.0.0
- FortiGate
- 7.0.3 and below
- 6.4.8 and below
- FortiNAC
- 8.3.7
- 8.5.0 - 8.5.2
- 8.5.4
- 8.6.0
- 8.6.2 - 8.6.5
- 8.7.0 - 8.7.6
- 8.8.0 - 8.8.11
- 9.1.0 - 9.1.5
- 9.2.0 - 9.2.2
- FortiIsolator
- 2.3.2 and below
- FortiClientWindows
- 6.0.X
- 6.2.X
- 6.4.0 - 6.4.6
- 7.0.0 - 7.0.2
An attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack
- Man-in-the-middle (MITM)
- Gather sensitive information
- SQL Injection
- Arbitrary code exaction
The CERT team encourages users to review Fortinet security advisory and apply the necessary updates:
- https://www.fortiguard.com/psirt/FG-IR-22-007
- https://www.fortiguard.com/psirt/FG-IR-22-041
- https://www.fortiguard.com/psirt/FG-IR-21-230
- https://www.fortiguard.com/psirt/FG-IR-21-239
- https://www.fortiguard.com/psirt/FG-IR-21-147
- https://www.fortiguard.com/psirt/FG-IR-21-231
- https://www.fortiguard.com/psirt/FG-IR-22-062
- https://www.fortiguard.com/psirt/FG-IR-21-040
- https://www.fortiguard.com/psirt/FG-IR-21-154