Fortinet Product Security Update Advisory

Overview

 

An update has been released to address vulnerabilities in Fortinet Products. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2023-50176

  • FortiOS 7.4 versions: 7.4.0 (inclusive) ~ 7.4.3 (inclusive)
  • FortiOS 7.2 versions: 7.2.0 (inclusive) ~ 7.2.7 (inclusive)
  • FortiOS 7.0 versions: 7.0.0 (inclusive) ~ 7.0.13 (inclusive)

 

CVE-2024-23666

  • FortiAnalyzer 7.4 versions: 7.4.0 (inclusive) ~ 7.4.1 (inclusive)
  • FortiAnalyzer 7.2 versions: 7.2.0 (inclusive) ~ 7.2.4 (inclusive)
  • FortiAnalyzer 7.0 versions: 7.0.0 (inclusive) ~ 7.0.11 (inclusive)
  • FortiAnalyzer 6.4 versions: 6.4.0 (inclusive) ~ 6.4.14 (inclusive)

 

  • FortiAnalyzer-BigData 7.4 version: 7.4.0
  • FortiAnalyzer-BigData 7.2 versions: 7.2.0 (inclusive) ~ 7.2.6 (inclusive)
  • FortiAnalyzer-BigData 7.0 versions: 7.0 all versions
  • FortiAnalyzer-BigData 6.4 versions: 6.4 all versions
  • FortiAnalyzer-BigData 6.2 versions: 6.2 all versions

 

  • FortiManager 7.4 versions: 7.4.0 (inclusive) ~ 7.4.1 (inclusive)
  • FortiManager 7.2 versions: 7.2.0 (inclusive) ~ 7.2.4 (inclusive)
  • FortiManager 7.0 versions: 7.0.0 (inclusive) ~ 7.0.11 (inclusive)
  • FortiManager 6.4 versions: 6.4.0 (inclusive) ~ 6.4.14 (inclusive)

 

CVE-2024-36513

  • FortiClientWindows 7.2 versions: 7.2.0 (inclusive) ~ 7.2.4 (inclusive)
  • FortiClientWindows 7.0 versions: 7.0.0 (inclusive) ~ 7.0.12 (inclusive)
  • FortiClientWindows 6.4 versions: 6.4.0 (inclusive) ~ 6.4.10 (inclusive)

 

 

Resolved Vulnerabilities

 

FortiOS session pinning vulnerability that allows an unauthenticated attacker to hijack a user session via a phishing SAML authentication link (CVE-2023-50176)

FortiAnalyzer client-side server security coercion vulnerability in which an authenticated attacker with read-only privileges could perform sensitive actions via a crafted request (CVE-2024-23666)

FortiClient Windows privilege context switching error vulnerability that allows an authenticated user to escalate privileges via a lua autopatch script (CVE-2024-36513) 

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2023-50176

  • FortiOS 7.4 version: 7.4.4 or later version
  • FortiOS 7.2 version: 7.2.8 or later version
  • FortiOS 7.0 version: 7.014 or later version

 

CVE-2024-23666

  • FortiAnalyzer 7.4 version: 7.4.3 or later version
  • FortiAnalyzer 7.2 version: 7.2.6 or later version
  • FortiAnalyzer 7.0 version: 7.0.13 or later version
  • FortiAnalyzer 6.4 version: 6.4.15 or later version

 

  • FortiAnalyzer-BigData 7.4 version: 7.4.1 or later version
  • FortiAnalyzer-BigData 7.2 version: 7.2.7 or later version
  • FortiAnalyzer-BigData 7.0 version: migrating to a fixed release
  • FortiAnalyzer-BigData 6.4 version: migrating to a fixed release
  • FortiAnalyzer-BigData 6.2 version: migrating to a fixed release

 

  • FortiManager 7.4 version: 7.4.3 or later version
  • FortiManager 7.2 version: 7.2.6 or later version
  • FortiManager 7.0 version: 7.0.13 or later version
  • FortiManager 6.4 version: 6.4.15 or later version

 

CVE-2024-36513

  • FortiClientWindows 7.2 version: 7.2.5 or later version
  • FortiClientWindows 7.0 version: 7.0.13 or later version
  • FortiClientWindows 6.4 version: migrating to a fixed release

 

 

References Sites

 

[1] CVE-2023-50176 Detail

https://nvd.nist.gov/vuln/detail/CVE-2023-50176

[2] FortiOS – SSLVPN session hijacking using SAML authentication

https://fortiguard.fortinet.com/psirt/FG-IR-23-475

[3] CVE-2024-23666 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23666

[4] Readonly users could run some sensitive operations

https://fortiguard.fortinet.com/psirt/FG-IR-23-396

[5] CVE-2024-36513 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-36513

[6] Privilege escalation via lua auto patch function

https://fortiguard.fortinet.com/psirt/FG-IR-24-144