Rewterz
Rewterz Threat Advisory – CVE-2023-25605 – Fortinet FortiSOAR Vulnerability
March 9, 2023
Rewterz
Rewterz Threat Alert – STOP (DJVU) Ransomware – Active IOCs
March 9, 2023

Rewterz Threat Advisory – Multiple Fortinet FortiOS and Fortinet FortiProxy Vulnerability

Severity

High

Analysis Summary

CVE-2022-42476 CVSS:8.2

Fortinet FortiOS and Fortinet FortiProxy could allow a local authenticated attacker to gain elevated privileges on the system, caused by a relative path traversal vulnerability. By using specially crafted CLI requests, an attacker could exploit this vulnerability to gain Super Admin privileges of the box.

CVE-2023-25610 CVSS:9.8

Fortinet FortiOS and FortiProxy could allow a remote attacker to execute arbitrary code on the system, caused by a heap buffer underflow in administrative interface. By sending specially-crafted requests, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the GUI.

Impact

  • Privilege Escalation
  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2022-42476
  • CVE-2023-25610

Affected Vendors

Fortinet

Affected Products

  • Fortinet FortiOS 6.2.8
  • Fortinet FortiProxy 1.0
  • Fortinet FortiOS 6.4.8
  • Fortinet FortiOS 6.4.9
  • Fortinet FortiProxy 2.0.0
  • Fortinet FortiProxy 1.1
  • Fortinet FortiOS 7.0.0
  • Fortinet FortiProxy 7.0.0

Remediation

Refer to FortiGuard Advisory for patch, upgrade or suggested workaround information. 

CVE-2022-42476

CVE-2023-25610