Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2023.2086 FortiWeb - XSS vulnerability in HTML generated attack report files 12 April 2023 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: FortiWeb Publisher: Fortinet Operating System: Network Appliance Resolution: Patch/Upgrade CVE Names: CVE-2022-43955 Original Bulletin: https://fortiguard.fortinet.com/psirt/FG-IR-22-428 Comment: CVSS (Max): 8.0 CVE-2022-43955 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) CVSS Source: Fortinet Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - --------------------------BEGIN INCLUDED TEXT-------------------- FortiWeb - XSS vulnerability in HTML generated attack report files IR Number : FG-IR-22-428 Date : Apr 11, 2023 Severity : High CVSSv3 Score : 8 Impact : Execute unauthorized code or commands CVE ID : CVE-2022-43955 Affected Products: FortiWeb: 7.0.3, 7.0.2, 7.0.1, 7.0.0, 6.4.2, 6.4.1, 6.4.0, 6.3.9, 6.3.8, 6.3.7, 6.3.6, 6.3.5, 6.3.4, 6.3.3, 6.3.21, 6.3.20, 6.3.2, 6.3.19, 6.3.18, 6.3.17, 6.3.16, 6.3.15, 6.3.14, 6.3.13, 6.3.12, 6.3.11, 6.3.10, 6.3.1, 6.3.0, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.1.3, 6.1.2, 6.1.1, 6.1.0, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0 Summary An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface may allow an unauthenticated and remote attacker to perform a reflected cross site scripting attack (XSS) via injecting malicious payload in log entries used to build report. Affected Products FortiWeb version 7.0.0 through 7.0.3 FortiWeb 6.4 all versions FortiWeb version 6.3.0 through 6.3.21 FortiWeb version 6.2 all versions FortiWeb version 6.1 all versions FortiWeb version 6.0 all versions Solutions Please upgrade to FortiWeb version 7.2.0 or above Please upgrade to FortiWeb version 7.0.4 or above Please upgrade to FortiWeb version 6.3.22 or above Timeline 2023-03-21: Initial publication - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: https://auscert.org.au/gpg-key/ iQIVAwUBZDYWiskNZI30y1K9AQgzuBAAuM+etcSwgbrup73t/+FcR3lI/jTzZGZA zUOVkFVw1YID1wBeenzYG+6r1wxpfbhNEkFUF+beMi77m63fWIdr5AIx1GaqDed9 TwVmv1+EFThjPGxb7Ykp8G1KpitB5gt5TnfJwIxx3DRxXXPh4ig2beN9PAtzCg9m Q0+vobdtk5eZpqE7XoSwsKqC27SYODaEHur0dG3lcQwMdMlEfYNLVcYYCb37eQJO w51NXy7tjRnrGZBkIwwAwsTVOEAXpWIZIPzqoD2Jd/sVYaH6K2pfvohur1xMxNH3 hPiSq1sZpo7LA2dfKDhCNchQNG6LtPw6awFk7A2oFY6CnO2EOB+9tt7ZXfhP1un1 zfnfDHaBRYHLr57a4Aayi9nCZ70GjCffl6j8wQwV7xbcgkQl5ty5STVp2Pgmc4Lx FAdAwHkPNblMwqZOoVqC8WZapRTet7DfdMOtfiZdLrhREyzL1IP1m3rPa8U0A/ul +nDJOib/HQNzMu/2T0JHNtI4UX8te/dYVKrCiH57UPTWLT+WIQgUGMbB+/Omr93O Le7WLJyhRc6vUUc57AidWldU1rFUGdO37W2EvQM7rGtogddZHQvjj1xQupnavjBq QwqxRXft6xfKzRVE0/2O7TEWcnhHGh9kqPdGQrYR8aAlWx1JUaU2zeTQtOZR4uOR gUUh1fcfWVA= =q8cc -----END PGP SIGNATURE-----