보안 권고문

Fortinet 제품군(FortiOS, FortiProxy) 보안 업데이트 권고

개요

 

Fortinet 제품군에서 발생하는 취약점을 해결하는 업데이트가 제공되었습니다. 해당하는 버전 사용자는 최신 버전으로 업데이트하시기 바랍니다.

 

대상 제품

 

CVE-2024-23112

  • FortiOS 7.4.0~7.4.1 버전
  • FortiOS 7.2.0~7.2.6 버전
  • FortiOS 7.0.1~7.0.13 버전
  • FortiOS 6.4.7~6.4.14 버전
  • FortiProxy 7.4.0~7.4.2 버전
  • FortiProxy 7.2.0~7.2.8 버전
  • FortiProxy 7.0.0~7.0.14 버전

 

CVE-2023-42789, CVE-2023-42790

  • FortiOS 7.4.0~7.4.1 버전
  • FortiOS 7.2.0~7.2.5 버전
  • FortiOS 7.0.0~7.0.13 버전
  • FortiOS 6.4.0~6.4.14 버전
  • FortiOS 6.2.0~6.2.15 버전
  • FortiProxy 7.4.0 버전
  • FortiProxy 7.2.0~7.2.6 버전
  • FortiProxy 7.0.0~7.0.12 버전
  • FortiProxy 2.0.0~2.0.13 버전

 

해결된 취약점

 

FortiOS 및 FortiProxy SSLVPN의 사용자 제어 키 취약점을 통한 인증 우회로 인해 인증된 공격자가 URL 조작을 통해 다른 사용자의 북마크에 액세스 가능한 취약점 (CVE-2024-23112)

FortiOS 및 FortiProxy captive portal의 스택 기반 버퍼 오버플로우로 인한 공격자가 조작된 HTTP 요청을 통해 승인되지 않은 코드나 명령을 실행 시킬 수  있는 취약점 (CVE-2023-42789, CVE-2023-42790)

 

취약점 패치

 

CVE-2024-23112

  • FortiOS 7.4.2 이상의 7.4.x 버전
  • FortiOS 7.2.7 이상의 7.2.x 버전
  • FortiOS 7.0.14 이상의 7.0.x 버전
  • FortiOS 6.4.15 이상의 6.4.x 버전
  • FortiProxy 7.4.3 이상의 7.4.x 버전
  • FortiProxy 7.2.9 이상의 7.2.x 버전
  • FortiProxy 7.0.15 이상의 7.0.x 버전

 

CVE-2023-42789, CVE-2023-42790

  • FortiOS 7.4.2 이상의 7.4.x 버전
  • FortiOS 7.2.6 이상의 7.2.x 버전
  • FortiOS 7.0.13 이상의 7.0.x 버전
  • FortiOS 6.4.15 이상의 6.4.x 버전
  • FortiOS 6.2.16 이상의 6.2.x 버전
  • FortiProxy 7.4.1 이상의 7.4.x 버전
  • FortiProxy 7.2.7 이상의 7.2.x 버전
  • FortiProxy 7.0.13 이상의 7.0.x 버전
  • FortiProxy 2.0.14 이상의 2.0.x 버전

 

참고 사이트

 

[1] FortiOS & FortiProxy – Authorization bypass in SSLVPN bookmarks

https://www.fortiguard.com/psirt/FG-IR-24-013

[2] FortiOS & FortiProxy – Out-of-bounds Write in captive portal

https://www.fortiguard.com/psirt/FG-IR-23-328

[3] CVE-2023-42789

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42789

[4] CVE-2023-42790

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42790