May 5, 2025
Trending News

Fortinet warns of critical vulnerability in FortiOS and FortiProxy

  • March 13, 2023
  • 0

Fortinet’s FortiOS and FortiProxy contain a critical vulnerability that an attacker could exploit to run proprietary code. Fortinet warns customers about a dangerous vulnerability in FortiOS and FortiProxy.

Fortinet’s FortiOS and FortiProxy contain a critical vulnerability that an attacker could exploit to run proprietary code.

Fortinet warns customers about a dangerous vulnerability in FortiOS and FortiProxy. This allows attackers to run their own code on the devices without authentication. Hackers can also compromise the functionality of vulnerable devices. The vulnerability is based on a buffer overflow bug and has the designation CVE-2023-25610, along with a score of 9.3. That officially makes the bug critical, which should give high priority to patching. At this point, hackers would not yet exploit the vulnerability in the wild.

The following products are affected:

  • FortiOS 7.2.0 to 7.2.3
  • FortiOS 7.0.0 to 7.0.9
  • FortiOS 6.4.0 to 6.4.11
  • FortiOS 6.2.0 to 6.2.12
  • FortiOS 6.0 (all versions)
  • FortiProxy 7.2.0 to 7.2.2
  • FortiProxy 7.0.0 to 7.0.8
  • FortiProxy 2.0.0 to 2.0.11
  • FortiProxy 1.2 (all versions)
  • FortiProxy 1.1 (all versions)

Fortinet has updates for affected products. If, for one reason or another, you cannot install it right away, it’s a good idea to disable HTTP/HTTPS for the management interface and manually limit the number of IP addresses that can access vulnerable products.

Patch fast

Vulnerabilities that allow attackers to gain a foothold in a network without stolen credentials are popular. So rest assured that it won’t be long before criminals launch campaigns based on the vulnerability. Due to the critical nature of the bug, patching should be an absolute priority.

Source: IT Daily

Leave a Reply

Your email address will not be published. Required fields are marked *

Exit mobile version