CyberzSOC

Publication detail
← Back to advisories & guidance

Fortinet Releases Security Updates for Multiple Products ↗ source

March 12, 2024 CISA Alert

Summary

A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system. FR-IR-23-390: FortiClientEMS - CSV injection in log download feature FR-IR-23-390: FortiClientEMS - CSV injection in log download feature FR-IR-23-328: FortiOS, FortiProxy - Out-of-bounds Write in captive portal FR-IR-23-328: FortiOS, FortiProxy - Out-of-bounds Write in captive portal FR-IR-24-013: FortiOS, FortiProxy - Authorization bypass in SSLVPN bookmarks FR-IR-24-013: FortiOS, FortiProxy - Authorization bypass in SSLVPN bookmarks FR-IR-23-103: FortiWLM MEA for FortiManager - Improper access control in backup and restore features FR-IR-23-103: FortiWLM MEA for FortiManager - Improper access control in backup and restore features FR-IR-24-007: Pervasive SQL injection in DAS component FR-IR-24-007: Pervasive SQL injection in DAS component This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.