Rewterz
Rewterz Threat Advisory – Multiple Fortinet FortiOS, FortiProxy and Fortiweb Vulnerabilities
June 13, 2023
Rewterz
Rewterz Threat Advisory – Multiple Fortinet FortiNAC Vulnerabilities
June 13, 2023

Rewterz Threat Advisory – Multiple Fortinet FortiADC and FortiADC Manager Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-26210 CVSS:7.8

Fortinet FortiADC and FortiADC Manager could allow a local authenticated attacker to execute arbitrary code on the system, caused by an OS command injection flaw. By sending specially crafted CLI requests, an attacker could exploit this vulnerability to execute arbitrary shell code as root user.

CVE-2023-28000 CVSS:6.7

Fortinet FortiADC could allow a local authenticated attacker to execute arbitrary commands on the system, caused by an OS command injection flaw in the CLI. By sending specially crafted arguments in diagnose system df CLI command, an attacker could exploit this vulnerability to execute arbitrary commands on the system.

Impact

  • Code Execution
  • Command Execution

Indicators Of Compromise

CVE

  • CVE-2023-26210
  • CVE-2023-28000

Affected Vendors

Fortinet

Affected Products

  • Fortinet FortiADCManager 5.3.0
  • Fortinet FortiADC 7.0.0
  • Fortinet FortiADC 6.1
  • Fortinet FortiADC 6.0
  • Fortinet FortiADC 5.4
  • Fortinet FortiADC 5.3
  • Fortinet FortiADC 5.2
  • Fortinet FortiADC 7.1.0
  • Fortinet FortiADC 7.1.2
  • Fortinet FortiADC 6.2.0
  • Fortinet FortiADCManager 5.2
  • Fortinet FortiADCManager 5.4
  • Fortinet FortiADCManager 6.0
  • Fortinet FortiADCManager 6.1
  • Fortinet FortiADCManager 6.2
  • Fortinet FortiADCManager 7.0.0
  • Fortinet FortiADCManager 7.1.0

Remediation

Upgrade to the latest version of FortiOS, available from the Fortinet Web site.

Fortinet Web site