ZeroHour
Security Affairspublished ()ingested @securityaffairs

Fortinet fixed a critical vulnerability in its Data Analytics product

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-27487
A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.

A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests.

NVD description · AI analysis pending
8.8<1%
  • fortinet fortideceptor
  • fortinet fortisandbox
CVE-2022-41331
+1 in the same advisory: …41330
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthentica

A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.

NVD description · AI analysis pending
9.8
group max
1%
  • fortinet fortiproxy
CVE-2022-43955
An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all version

An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote attacker to perform a reflected cross site scripting attack (XSS) via injecting malicious payload in log entries used to build report.

NVD description · AI analysis pending
6.1<1%
  • fortinet fortiweb
Full article295 words · extracted from securityaffairs.com · click to collapse

Fortinet addressed a critical vulnerability that can lead to remote, unauthenticated access to Redis and MongoDB instances.

Fortinet has addressed a critical vulnerability, tracked as CVE-2022-41331 (CVSS score of 9.3), in its Fortinet FortiPresence data analytics solution.

FortiPresence is a comprehensive data analytics solution designed for analyzing user traffic and deriving usage patterns.

Successful exploitation can lead to remote, unauthenticated access to Redis and MongoDB instances via crafted authentication requests.

“A missing authentication for critical function vulnerability [CWE-306] in FortiPresence on-prem infrastructure server may allow a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.” reads the advisory published by the vendor.

The vulnerability affects FortiPresence 1.2 all versions, FortiPresence 1.1 all versions, and FortiPresence 1.0 all versions. The company added that Cloud instances of FortiPresence are not impacted.

Fortinet addressed multiple vulnerabilities in its products as part of its “April 2023 Vulnerability Advisories,” below are the most severe ones:

  • CVE-2022-43955 (CVSS score of 8) – FortiWeb – XSS vulnerability in HTML generated attack report files
  • CVE-2022-27487 (CVSS score of 8.3) FortiSandbox / FortiDeceptor – Improper profile-based access control over APIs
  • CVE-2022-41330 (CVSS score of 8.3) FortiOS & FortiProxy – Cross Site Scripting vulnerabilities in administrative interface

Customers are recommended to update their instances as soon as possible.

Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections:

  • The Teacher – Most Educational Blog
  • The Entertainer – Most Entertaining Blog
  • The Tech Whizz – Best Technical Blog
  • Best Social Media Account to Follow (@securityaffairs)

Please nominate Security Affairs as your favorite blog.

Nominate here: https://docs.google.com/forms/d/e/1FAIpQLSfaFMkrMlrLhOBsRPKdv56Y4HgC88Bcji4V7OCxCm_OmyPoLw/viewform

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Fortinet)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/144750/security/fortinet-critical-vulnerability-data-analytics.html