Fortinet warns of new RCE vulnerabilities
- July 13, 2023
- 0
The security company Fortinet warns of a stack buffer overflow vulnerability (CWE-124) in FortiOS and FortiProxy. A stack buffer overflow vulnerability has been found in both FortiOS and
The security company Fortinet warns of a stack buffer overflow vulnerability (CWE-124) in FortiOS and FortiProxy. A stack buffer overflow vulnerability has been found in both FortiOS and
The security company Fortinet warns of a stack buffer overflow vulnerability (CWE-124) in FortiOS and FortiProxy.
A stack buffer overflow vulnerability has been found in both FortiOS and FortiProxy. Fortinet reports this after being informed by another security company, Watchtowr. In addition to Fortinet’s PSIRT Advisory, the American Cybersecurity & Infrastructure Security Agency also issued an additional warning.
The vulnerability is named CVE-2023-33308 and scores a solid 9.8 out of 10 on the CVSSv3 scale, making it quite critical. Attackers can exploit them to remotely execute malicious code. Another danger is that the proxy or the firewall can be attacked via data packets.
Fortinet listed products that may be affected:
Solutions are provided in the upgrades of the following systems:
For those who are unable to install an update yet, Fortinet recommends disabling HTTP/2 support for SSL inspection profiles used by proxy policies or firewall policies in proxy mode.
Therefore, updating whenever possible remains extremely important. Earlier this month, we reported on the potential impact of procrastination on admins and IT teams: hundreds of thousands of vulnerable firewalls. Fortinet also recently added firewalls to its flexible licensing program.
Source: IT Daily
As an experienced journalist and author, Mary has been reporting on the latest news and trends for over 5 years. With a passion for uncovering the stories behind the headlines, Mary has earned a reputation as a trusted voice in the world of journalism. Her writing style is insightful, engaging and thought-provoking, as she takes a deep dive into the most pressing issues of our time.