Multiple Vulnerabilities in Fortinet Products Could Allow for Remote Code Execution
ID: 82214261-f30e-5e3a-b46a-7d9d95e40e0f
STIX ID: report--82214261-f30e-5e3a-b46a-7d9d95e40e0f
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities were disclosed across Fortinet products (FortiSwitch, FortiIsolator, FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiVoice, FortiWeb, FortiClient, and FortiWeb endpoint) that include high-impact issues such as remote code execution, unauthenticated admin password modification, and FGFM authentication interception leading to management impersonation (several CVEs listed). Lower-severity issues include log injection, credential exposure via LDAP misconfiguration, XSS, path traversal, and SSLVPN memory corruption. Successful exploitation could allow attackers to run code, modify or exfiltrate data, and disrupt device management depending on privileges and deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
