AUf Grund einer gemeldeten Sicherheitslücke in FortiOS wurde die Firewall auf Version 7.0.10 aktualisiert.
Fortinet has disclosed a critical vulnerability impacting FortiOS and FortiProxy. In short, the vulnerability CVE-2023-25610 has a CVSS v3 score of 9.3, rating it critical, allowing an unauthenticated attacker to execute arbitrary code or perform denial of service (DoS) on the GUI of vulnerable devices using specially crafted requests.
Affected products:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
FortiOS version 6.4.0 through 6.4.11
FortiOS version 6.2.0 through 6.2.12
FortiOS 6.0, all versions
FortiProxy version 7.2.0 through 7.2.2
FortiProxy version 7.0.0 through 7.0.8
FortiProxy version 2.0.0 through 2.0.11
FortiProxy 1.2, all versions
FortiProxy 1.1, all versions
Fortinet says that fifty device models, listed in their security bulletin, are not impacted by the arbitrary code execution component of the flaw but only the denial of service part, even if they run a vulnerable FortiOS version.





