Date version

Produits Fortinet

Des vulnérabilités ont été découvertes dans les produits Fortinet. L'exploitation de ces failles pourrait permettre à un attaquant distant d'exécuter du code arbitraire et de provoquer une atteinte à la confidentialité des données. NB: La faille CVE-2024-55591 est activement exploitée.
 

  • Refer
    tunCERT/Vuln.2025-026
    Version
    1.0
    Date de publication
Impact
Déni de service
Exécution de code arbitraire
Obtention de privilèges
Perte d'intégrité
Perte de confidentialité
Plateforme
Indépendant de la Plate-forme
Produits impactés

FortiManager antérieures à 7.6.2, 7.4.6, 7.4.5, 7.2.9, 7.2.8, 7.0.13, 6.4.13

FortiAnalyzer antérieures à 7.4.4, 7.2.6, 7.0.13

FortiOS antérieures à 7.6.1, 7.0.17, 7.4.5, 7.2.10

FortiProxy antérieures à 7.2.13, 7.0.20, 7.4.5, 2.0.15

FortiClientLinux antérieures à 7.4.0, 7.2.5

FortiClientMac antérieures à 7.4.0, 7.2.5

FortiClientWindows antérieures à 7.2.3, 7.0.10

FortiSOAR antérieures à 7.4.2, 7.3.3

FortiClientEMS antérieures à 7.2.5, 7.0.11

FortiManager Cloud antérieures à 7.4.3, 7.2.7, 7.0.13

FortiSwitch antérieures à 7.4.1, 7.2.6, 7.0.8, 6.4.14, 6.2.8

FortiSandbox antérieures à 4.4.5, 4.2.7, 4.0.5

FortiRecorder antérieures à 7.2.2, 7.0.5,

FortiVoice antérieures à 7.0.5, 6.4.10

FortiWeb antérieures à 7.6.1, 7.4.5

Identificants du problème
    • CVE-2024-47571 CVE-2024-36512 CVE-2024-55591 CVE-2023-4863 CVE-2024-46662 CVE-2024-23106 CVE-2023-37936 CVE-2024-47572 CVE-2024-35277 CVE-2024-46668 CVE-2024-50566 CVE-2024-27778 CVE-2024-46670 CVE-2024-35273 CVE-2024-48884 CVE-2024-48886 CVE-2023-37937
    • CVE-2024-50563 CVE-2024-48885 CVE-2024-54021 CVE-2023-46715 CVE-2023-42786 CVE-2023-42785 CVE-2024-36504 CVE-2024-46666
Solution vulnérabilités