CISA Activity - Fortinet Releases Security Updates for Multiple Products

  • Welcome to ITBible, we're your #1 resource for enterprise or homelab IT problems (or just a place to show off your stuff).


Fortinet has released security advisories addressing vulnerabilities in multiple products. These vulnerabilities may allow cyber threat actors to take control of the affected systems.

CISA encourages users and administrators to review the following Fortinet security advisories and apply the recommended updates:

  • FG-IR-23-189: FortiManager, FortiAnalyzer – Path traversal via unrestricted file upload
  • FG-IR-23-062: FortiManager – Improper inter ADOM access control
  • FG-IR-23-167: FortiManager, FortiAnalyzer – OS command injection
  • FG-IR-22-352: FortiManager, FortiAnalyzer, FortiADC – Command injection due to an unsafe usage of function
  • FG-IR-23-318: FortiOS – Improper authorization via prof-admin profile

Continue reading...