Summary
New vulnerabilities have been discovered in various products, including 4 with a “high” severity. These vulnerabilities could allow bypassing security mechanisms, executing arbitrary commands, and elevating user privileges on affected systems.
Risk
Estimate of the vulnerability’s impact on the target community: MEDIUM/YELLOW (63.33/100)1.
Type
- Security Restrictions Bypass
- Privilege Escalation
- Arbitrary Code Execution
Affected Products and Versions
- FortiAnalyzer 7.4.x, from version 7.4.0 to 7.4.1
- FortiAnalyzer 7.2.x, from version 7.2.0 to 7.2.4
- FortiAnalyzer 7.0.x, from version 7.0.0 to 7.0.11
- FortiAnalyzer 6.4.x, from version 6.4.0 to 6.4.14
- FortiAnalyzer-BigData 7.4.x, from version 7.4.0
- FortiAnalyzer-BigData 7.2.x, from version 7.2.0 to 7.2.6
- FortiAnalyzer-BigData 7.0.x, from version 7.0 all versions
- FortiAnalyzer-BigData 6.4.x, from version 6.4 all versions
- FortiAnalyzer-BigData 6.2.x, from version 6.2 all versions
- FortiManager 7.4.x, from version 7.4.0 to 7.4.1
- FortiManager 7.2.x, from version 7.2.0 to 7.2.4
- FortiManager 7.0.x, from version 7.0.0 to 7.0.11
- FortiManager 6.4.x, from version 6.4.0 to 6.4.14
- FortiClientWindows 7.4.0
- FortiClientWindows 7.2.x, from version7.2.0 to 7.2.4
- FortiClientWindows 7.0.x, from version7.0.0 to 7.0.12
- FortiClientWindows 6.4.x, all versions
- FortiOS 7.4.x, from version 7.4.0 to 7.4.3
- FortiOS 7.2.x, from version 7.2.0 to 7.2.7
- FortiOS 7.0.x, from version 7.0.0 to 7.0.13
Mitigations
In line with vendor statements, it is recommended to apply mitigations following the guidance of the security bulletins available in the References section.
Unique Vulnerability Identifiers
References
https://fortiguard.fortinet.com/psirt/FG-IR-23-396
https://fortiguard.fortinet.com/psirt/FG-IR-24-144
https://fortiguard.fortinet.com/psirt/FG-IR-24-199
https://fortiguard.fortinet.com/psirt/FG-IR-23-475
1This estimate is made taking into account several parameters, including: CVSS, availability of patches/workarounds and PoC, diffusion of the affected software/devices in the reference community.