Fortinet (FortiSIEM, FortiOS, FortiProxy, FortiClientEMS) Security Update Advisory (CVE-2024-23109, CVE-2023-45581, CVE-2023-44250)

Overview

 

An update is available to address vulnerabilities in Fortinet (FortiSIEM, FortiOS, FortiProxy, FortiClientEMS). users of affected versions are encouraged to update to the latest version.

 

Affected Products

 

CVE-2024-23109

  • FortiSIEM versions 7.1.0 through 7.1.1
  • FortiSIEM 7.0.0 through 7.0.2 Versions
  • FortiSIEM versions 6.7.0 through 6.7.8
  • FortiSIEM 6.6.0 through 6.6.3 Versions
  • FortiSIEM 6.5.0 through 6.5.2 Versions
  • FortiSIEM 6.4.0 through 6.4.2 versions

 

CVE-2023-45581

  • FortiClientEMS 7.2.0 through 7.2.2 Versions
  • FortiClientEMS 7.0.6 through 7.0.10 Versions
  • FortiClientEMS 7.0.0 through 7.0.4 Versions
  • All versions of FortiClientEMS 6.4
  • All versions of FortiClientEMS 6.2

 

CVE-2023-44250

  • FortiOS versions 7.4.0 through 7.4.1
  • FortiOS 7.2.5 and later
  • FortiProxy versions 7.4.0 through 7.4.1

 

Resolved Vulnerabilities

 

Multiple remote unauthenticated OS command injection vulnerability in FortiSIEM (CVE-2024-23109)
Improper privilege management vulnerability for site super administrators in FortiClientEMS (CVE-2023-45581)
Improper authorization vulnerability for HA requests in FortiOS and FortiProxy (CVE-2023-44250)

 

Vulnerability Patches

 

Vulnerability patches were made available in the January 9, January 31, and February 8, 2024 updates. please follow the instructions on the reference site to update to the latest vulnerability patch version.

 

CVE-2024-23109

  • FortiSIEM versions 7.1.3, 7.0.3, and 6.7.9
  • FortiSIEM versions 7.2.0, 6.6.5, 6.5.3, 6.4.4 (coming soon)

 

CVE-2023-45581

  • FortiClientEMS version 7.2.3
  • FortiClientEMS 7.0.11 version

 

CVE-2023-44250

  • FortiOS version 7.4.2
  • FortiOS 7.2.6
  • FortiProxy version 7.4.2

 

reference sites

 

[1] FortiOS & FortiProxy – Improper authorization for HA requests
https://www.fortiguard.com/psirt/FG-IR-23-315
[2] FortiClientEMS – Improper privilege management for site super administrator
https://www.fortiguard.com/psirt/FG-IR-23-357
[3] FortiSIEM – Multiple remote unauthenticated os command injection
https://www.fortiguard.com/psirt/FG-IR-23-130