Fortinet disclosed five vulnerabilities this week, two of which are rated “critical.” The Cybersecurity and Infrastructure Security Agency (CISA) also issued an advisory warning that threat actors could exploit some of these vulnerabilities to take control of an affected system.

One of the vulnerabilities with a severity rating of critical is a pervasive SQL injection flaw within the DAS component of FortiClient Enterprise Management Server (FortiClientEMS) software. This vulnerability, identified as CVE-2023-48788, has a CVSSv3 score of 9.3.

Initially disclosed on February 22, and further detailed on March 12, this critical SQL injection vulnerability could allow an unauthenticated remote attacker to execute commands or arbitrary code through specifically crafted requests on vulnerable FortiClientEMS software.

Fortinet released patches to mitigate the risk posed by the vulnerability, and has urged users to upgrade their systems to the secure versions as soon as possible. Specifically, FortiClientEMS versions 7.2.0 through 7.2.2 and versions 7.0.1 through 7.0.10 are advised to upgrade to versions 7.2.3 and 7.0.11 or above, respectively.

In addition to this SQL injection vulnerability, Fortinet also addressed an out-of-bounds write vulnerability and a Stack-based Buffer Overflow in its FortiOS and FortiProxy captive portal. The flaws were identified as CVE-2023-42789 and CVE-2023-42790 and received a CVSSv3 score of 9.3.

The vulnerabilities could allow an inside attacker who has access to captive portal to execute arbitrary code or commands via specially crafted hypertext transfer protocol (HTTP) requests.

The affected products include Fortinet’s FortiOS operating system (OS) version 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, and 6.2.0 through 6.2.15; as well as its secure web proxy FortiProxy version 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, and 2.0.0 through 2.0.13.

The company advised users to update to the secure versions. It also released a virtual patch named “FortiOS.Captive.Portal.Out.Of.Bounds.Write.,” which is available in FMWP db update 23.105.

Fortinet remedied this issue in its secure access service edge (SASE) solution FortiSASE version 23.3.b during the third quarter of 2023, so those customers no longer need to take any actions.

Fortinet and CISA also warned of three more vulnerabilities with a severity rating of high. This includes:

  • A CSV File vulnerability (CVE-2023-47534) in FortiClientEMS with a CVSSv3 score of 8.7 that may allow a remote and unauthenticated attacker to execute arbitrary commands on the admin workstation via creating malicious log entries with crafted requests to the server.
  • An authorization bypass through user-controlled key vulnerability (CVE-2024-23112) in FortiOS and FortiProxy SSLVPN with a CVSSv3 score of 7.2 that may allow an authenticated attacker to gain access to another user’s bookmark via URL manipulation.
  • An improper access control vulnerability (CVE-2023-36554) in FortiWLM MEA for FortiManager with a CVSSv3 score of 7.7 that may allow an unauthenticated remote attacker to execute arbitrary code or commands via specifically crafted requests.

CISA urges users and administrators to review the advisories and apply necessary updates.