Cybersecurity provider, Fortinet, fixed six highly rated vulnerabilities of the 16 total issues discovered in various company products.

One of the high-severity issues is a persistent cross-site scripting issue (CVE-2022-3837) in Log pages of FortiADC. A remote, unauthenticated attacker could trigger the flaw to perform a stored XSS attack via HTTP fields observed in the traffic and event logviews.

Another issue rated high is in FortiTester (CVE-2022-33870) which could allow an authenticated attacker to execute commands via specially crafted arguments to existing commands.

A high-rated vulnerability with a case number of CVE-2022-26119 affects FortiSIEM, where a local attacker with command-line access can exploit the bug to perform operations on the Glassfish server directly via a hardcoded password.

Another high rated vulnerability is an improper neutralization of input during web page generation vulnerability in FortiADC management interface that may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted IP Address.

Schneider Bold

Products affected by the vulnerability, which has a case number of CVE-2022-35851, are FortiADC version 7.1.0, with a fix in version 7.1.1 or above.

Click here for more in the other vulnerabilities.

ISSSource

Pin It on Pinterest

Share This