{"id":3087,"date":"2022-07-11T09:17:38","date_gmt":"2022-07-11T14:17:38","guid":{"rendered":"https:\/\/cert.pa\/?p=3087"},"modified":"2022-07-11T09:17:38","modified_gmt":"2022-07-11T14:17:38","slug":"csirt-panama-aviso-2022-07-11-fortinet-vulnerabilidades-de-alto-riesgo-en-productos-fortinet","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=3087","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2022-07-11 Fortinet: Vulnerabilidades de alto riesgo en productos Fortinet"},"content":{"rendered":"\n<p>CSIRT Panam\u00e1 Aviso 2022-07-11 Fortinet: Vulnerabilidades de alto riesgo en productos Fortinet<\/p>\n\n\n\n<p>Gravedad: Alta<br>Fecha de publicaci\u00f3n: Julio 11, 2022<br>\u00daltima revisi\u00f3n: Julio 11, 2022<br>Sitio web: https:\/\/www.fortinet.com\/lat<br>Sistemas Afectados:<\/p>\n\n\n\n<p>\u2022 FortiAnalyzer, FortiManager, FortiOS y FortiProxy.<br>\u2022 FortiClient.<br>\u2022 FortiDeceptor versiones 1.0.0 a 4.0.1.<br>\u2022 FortiNAC versiones 8.3.7 a 9.2.3<\/p>\n\n\n\n<p>I. Descripci\u00f3n<\/p>\n\n\n\n<p>Se han publicado m\u00faltiples vulnerabilidades de severidad alta, que afectan a diversos productos Fortinet.<\/p>\n\n\n\n<p>II. Impacto<\/p>\n\n\n\n<p>Vulnerabilidad CVE-2021-43072:<\/p>\n\n\n\n<p>Desbordamiento de buffer basado en lotes a trav\u00e9s de comandos CLI en FortiAnalyzer, FortiManager, FortiOS y FortiProxy<\/p>\n\n\n\n<p>Vulnerabilidad CVE-2021-41031:<\/p>\n\n\n\n<p>Escalamiento de privilegios en FortiClient (Windows) a trav\u00e9s de un ataque de directorio transversal (directory traversal attack).<\/p>\n\n\n\n<p>Vulnerabilidad CVE-2022-30302:<\/p>\n\n\n\n<p>Vulnerabilidades de salto de directorio (path traversal) en la interfaz de administraci\u00f3n de FortiDeceptor.<\/p>\n\n\n\n<p>Vulnerabilidad CVE-2022-26117:<\/p>\n\n\n\n<p>Posible ejecuci\u00f3n de c\u00f3digo o comandos no autorizados en bases de datos MySQL en FortiNAC.<\/p>\n\n\n\n<p>III. Referencia a soluciones, herramientas e informaci\u00f3n<\/p>\n\n\n\n<p>Actualizar a las versiones correspondientes:<\/p>\n\n\n\n<p>1.CVE-2021-43072: FortiAnalyzer, FortiManager, FortiOS y FortiProxy.<br>Enlace: https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-206<\/p>\n\n\n\n<p>2.CVE-2021-41031: FortiClient.<br>Enlace: https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-190<\/p>\n\n\n\n<p>3.CVE-2022-30302: FortiDeceptor versiones 1.0.0 a 4.0.1.<br>Enlace: https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-213<\/p>\n\n\n\n<p>4.CVE-2022-26117: FortiNAC versiones 8.3.7 a 9.2.3.<br>Enlace: https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-058<\/p>\n\n\n\n<p>Fuentes:<\/p>\n\n\n\n<p>1.CSIRT Nacional de Chile. 9VSA22-00672-01 CSIRT alerta de vulnerabilidades de alto riesgo en productos Fortinet. 8 de Julio del 2022. Recopilado en: https:\/\/www.csirt.gob.cl\/vulnerabilidades\/9vsa22-00672-01\/<\/p>\n\n\n\n<p>Informaci\u00f3n de contacto<\/p>\n\n\n\n<p>CSIRT PANAMA<br>Computer Security Incident Response Team Autoridad Nacional para la Innovacion Gubernamental<br>E-Mail: info@cert.pa<br>Phone: +507 520-CERT (2378)<br>Web: https:\/\/cert.pa<br>Twitter: @CSIRTPanama<br>Key ID: 16F2B124<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CSIRT Panam\u00e1 Aviso 2022-07-11 Fortinet: Vulnerabilidades de alto riesgo en productos Fortinet Gravedad: AltaFecha de publicaci\u00f3n: Julio 11, 2022\u00daltima revisi\u00f3n: Julio 11, 2022Sitio web: https:\/\/www.fortinet.com\/latSistemas Afectados: \u2022 FortiAnalyzer, FortiManager, FortiOS y FortiProxy.\u2022 FortiClient.\u2022 FortiDeceptor versiones&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1020,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[4],"tags":[76,8,72,68],"class_list":["post-3087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad","tag-actualizaciones","tag-avisos","tag-avisos-de-seguridad","tag-vulnerabilidades"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/3087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3087"}],"version-history":[{"count":1,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/3087\/revisions"}],"predecessor-version":[{"id":3088,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/3087\/revisions\/3088"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/1020"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}