漏洞更新 - Fortinet釋出FortiNAC安全漏洞更新(CVE-2023-33299)
Fortinet釋出FortiNAC安全漏洞更新(CVE-2023-33299)
一、摘要
FortiNAC 中不可信數據反序列化漏洞可能允許未經身份驗證的用戶通過特製的對 tcp/1050 服務的請求執行未經授權的代碼或命令。
二、存在風險
FortiNAC 中不可信數據反序列化漏洞可能允許未經身份驗證的用戶通過特製的對 tcp/1050 服務的請求執行未經授權的代碼或命令,影響版本如下:
- FortiNAC version 9.4.0 through 9.4.2
- FortiNAC version 9.2.0 through 9.2.7
- FortiNAC version 9.1.0 through 9.1.9
- FortiNAC version 7.2.0 through 7.2.1
- FortiNAC 8.8 all versions
- FortiNAC 8.7 all versions
- FortiNAC 8.6 all versions
- FortiNAC 8.5 all versions
- FortiNAC 8.3 all versions
更新版本:
- Please upgrade to FortiNAC version 9.4.3 or above
- Please upgrade to FortiNAC version 9.2.8 or above
- Please upgrade to FortiNAC version 9.1.10 or above
- Please upgrade to FortiNAC version 7.2.2 or above
- Please upgrade to FortiNAC version 9.4.3 or above
- Please upgrade to FortiNAC version 9.2.8 or above
- Please upgrade to FortiNAC version 9.1.10 or above
- Please upgrade to FortiNAC version 7.2.2 or above
建議改善措施:請維護廠商協助更新至已修復版本。
情資報告連結:https://www.fortiguard.com/psirt/FG-IR-23-074
建議改善措施:請維護廠商協助更新至已修復版本。
情資報告連結:https://www.fortiguard.com/psirt/FG-IR-23-074