By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Digital TrustDigital TrustDigital Trust
  • Cybersecurity
    • Incident response and recovery
    • Network security
    • Phishing attacks and social engineering
    • Malware and viruses
    • Cloud security
  • Emerging Tech
    • Quantum computing
    • Artificial intelligence and machine learning
    • Blockchain technology
    • Internet of Things (IoT)
    • Augmented and virtual reality
  • Data privacy
    • GDPR compliance
    • Data protection laws and regulations
    • Data breaches and cyber attacks
    • Privacy policies and terms of service
    • User consent and data sharing
  • Business
    • Cyber insurance
    • Cybersecurity budgeting
    • Risk management and assessment
    • Digital trust and brand reputation
    • Investment and funding in cybersecurity companies
  • Compliance
    • PCI DSS compliance
    • HIPAA compliance
    • GDPR compliance
    • CCPA compliance
    • Cybersecurity laws and regulations
  • Research Center
Reading: Nipping Cyber Threats in the Bud: Fortinet Quashes Major Vulnerabilities in FortiOS System
Share
Notification Show More
Font ResizerAa
Digital TrustDigital Trust
Font ResizerAa
  • Cybersecurity
    • Incident response and recovery
    • Network security
    • Phishing attacks and social engineering
    • Malware and viruses
    • Cloud security
  • Emerging Tech
    • Quantum computing
    • Artificial intelligence and machine learning
    • Blockchain technology
    • Internet of Things (IoT)
    • Augmented and virtual reality
  • Data privacy
    • GDPR compliance
    • Data protection laws and regulations
    • Data breaches and cyber attacks
    • Privacy policies and terms of service
    • User consent and data sharing
  • Business
    • Cyber insurance
    • Cybersecurity budgeting
    • Risk management and assessment
    • Digital trust and brand reputation
    • Investment and funding in cybersecurity companies
  • Compliance
    • PCI DSS compliance
    • HIPAA compliance
    • GDPR compliance
    • CCPA compliance
    • Cybersecurity laws and regulations
  • Research Center
Follow US
© 2024 Digital Trust, a Talk About Tech brand. All rights Reserved.
Digital Trust > Cybersecurity > Malware and viruses > Nipping Cyber Threats in the Bud: Fortinet Quashes Major Vulnerabilities in FortiOS System
CybersecurityMalware and virusesNetwork security

Nipping Cyber Threats in the Bud: Fortinet Quashes Major Vulnerabilities in FortiOS System

Conal Cram
Last updated: September 20, 2023 8:21 am
Conal Cram 2 years ago
Share
Fortinet Patches Serious Security Vulnerabilities
SHARE

Fortinet Mitigates Severe Vulnerabilities in FortiOS, FortiProxy, and FortiWeb

Fortinet, a pioneer in the cybersecurity arena, has recently patched a significant cross-site scripting (XSS) vulnerability (CVE-2023-29183) found across numerous versions of FortiOS and FortiProxy. This notable vulnerability, assigned a CVSS score of 7.3, could facilitate harmful JavaScript code execution through manipulated guest management settings, as confirmed by a Fortinet advisory.

Contents
Fortinet Mitigates Severe Vulnerabilities in FortiOS, FortiProxy, and FortiWebAffected Fortinet ProductsIssued Patches by FortinetAbout FortinetConclusion

“This may allow an authenticated attacker to trigger malicious JavaScript code execution via crafted guest management setting,” the cybersecurity firm cautioned.

On the same note, Fortinet has rectified a high-severity flaw that plagued its FortiWeb software. The flaw, identified as CVE-2023-34984 and armed with a CVSS score of 7.1, could potentially empower attackers to bypass XSS and CSRF protection. According to a warning issued by CISA, this vulnerability could enable cyber attackers to gain control over compromised systems.

Affected Fortinet Products

  • FortiProxy versions from 7.2.0 to 7.2.4, and from 7.0.0 to 7.0.10
  • FortiOS versions from 7.2.0 to 7.2.4, from 7.0.0 to 7.0.11, from 6.4.0 to 6.4.12, and from 6.2.0 to 6.2.14
  • FortiWeb versions from 7.2.0 to 7.2.1, and from 7.0.0 to 7.0.6, including all 6.4 and 6.3 versions

Issued Patches by Fortinet

  • FortiProxy versions 7.2.5 and 7.0.11 and above
  • FortiOS versions 7.4.0, 7.2.5, 7.0.12, 6.4.13, and 6.2.15 and above
  • FortiWeb versions 7.2.2 and 7.0.7 and above

Therefore, Fortinet recommends all its trusted customers to urgently update their switches and firewalls to safeguard their systems from potential threats that these vulnerabilities may pose.

About Fortinet

Fortinet (NASDAQ: FTNT) is a driving force in the evolution of cybersecurity and the convergence of networking and security. Our mission is to secure people, devices, and data everywhere, and today we deliver cybersecurity everywhere you need it with the largest integrated portfolio of over 50 enterprise-grade products. Well over half a million customers trust Fortinet’s solutions, which are among the most deployed, most patented, and most validated in the industry. The Fortinet Training Institute, one of the largest and broadest training programs in the industry, is dedicated to making cybersecurity training and new career opportunities available to everyone. FortiGuard Labs, Fortinet’s elite threat intelligence and research organization, develops and utilizes leading-edge machine learning and AI technologies to provide customers with timely and consistently top-rated protection and actionable threat intelligence. Learn more at https://www.fortinet.com, the Fortinet Blog, and FortiGuard Labs.

Conclusion

Ensuring a robust cybersecurity posture plays a vital role in our increasingly connected world. Keeping your software updated is the first line of defense. We’d love to hear your thoughts on this issue. Are you a Fortinet user, and have you updated your system? Please share your experiences in the comments below.

You Might Also Like

US Government Pledges $10 Million Reward for Information on Nation-State Cyberattacks

Cybersecurity Incident Response: The Key to Safeguarding Digital Trust

Wiz Opens European Headquarters in London, Aiming for Global Expansion

New GPU Attack in Browsers: A Security Wake-Up Call

Hackers Attempt Selling Data of 30 Million Santander Customers and Staff

Share This Article
Facebook Twitter Email Print
By Conal Cram
Follow:
Conal is a seasoned tech industry professional and content writer for numerous tech publications. With a strong background in software engineering and digital media development, he's passionate about sharing the latest updates and insights in the tech industry, particularly in artificial intelligence and other disruptive trends. In his spare time he loves a mezze platter and a good film, and if he's not playing Fortnite or spending time with his daughter you can assume he's at the dry slopes!
Previous Article Johnson Controls Debuts OpenBlue Advanced Device Monitoring Johnson Controls Debuts OpenBlue Service for Advanced Security Device Monitoring
Next Article CapraRAT Malware Takes Over Your Android Devices via YouTube Beware: The Sinister Side of YouTube – CapraRAT Malware Takes Over Your Android Devices
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts

Pax8 & CyberFOX: Leading the Future of IAM Solutions

Pax8 & CyberFOX: Leading the Future of IAM Solutions

By Conal Cram 3 Min Read

Google Privacy Settlements: Are You Owed Money?

By Josh Hatton 2 Min Read

Is AI Worth the Price of Trust in High-Tech Companies?

By Josh Hatton 3 Min Read

Zero Trust: The Ultimate Safeguard for Today’s Digital Networks

By Conal Cram 3 Min Read

From our research center

https://digitaltrust.media/wp-content/uploads/sites/15/2024/05/cyberark-banner.jpg
- Sponsored by -
CyberArk

2024 Playbook: Identity Security and Cloud Compliance

Cloud migration and digital transformation have become more commonplace among enterprises, but these initiatives raise new challenges to protect their data, applications and workloads.  This...

Read content
about us

Our dedicated team of experts and journalists brings in-depth analysis, breaking news, and comprehensive reports from around the globe.

Useful links

  • About us
  • Contact us
  • Research Center
  • Disclaimer
  • Terms & Conditions
  • Privacy

Trending topics

  • Cybersecurity
  • Emerging technologies
  • Data privacy
  • Regulations and compliance
  • Digital trust and brand reputation

Find Us on Socials

© 2024 Digital Trust, a Talk About Tech brand. All rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?