{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"FortiOS versions 7.4.x ant\u00e9rieures \u00e0 7.4.3","product":{"name":"FortiOS","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiProxy versions 7.4.x ant\u00e9rieures \u00e0 7.4.3","product":{"name":"FortiProxy","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiManager versions 7.4.x ant\u00e9rieures \u00e0 7.4.2","product":{"name":"FortiManager","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiAnalyzer versions 7.2.x ant\u00e9rieures \u00e0 7.2.4","product":{"name":"FortiAnalyzer","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiNAC 8.3, 8.5, 8.6, 8.7, 8.8, 9.1 et 9.2 toutes versions","product":{"name":"FortiNAC","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiProxy 1.1 toutes versions","product":{"name":"FortiProxy","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiNAC versions 7.2.x ant\u00e9rieures \u00e0 7.2.3","product":{"name":"FortiNAC","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiOS versions 7.0.x ant\u00e9rieures \u00e0 7.0.14 (Cette version reste affect\u00e9e par la vuln\u00e9rabilit\u00e9 CVE-2023-47537)","product":{"name":"FortiOS","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiAnalyzer versions 7.4.x ant\u00e9rieures \u00e0 7.4.2","product":{"name":"FortiAnalyzer","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiAnalyzer-BigData versions 7.2.x ant\u00e9rieures \u00e0 7.2.6","product":{"name":"FortiAnalyzer","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiPAM 1.0 toutes versions","product":{"name":"FortiPAM","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiProxy 1.2 toutes versions","product":{"name":"FortiProxy","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiOS versions 6.2.x ant\u00e9rieures \u00e0 6.2.16","product":{"name":"FortiOS","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiManager versions 7.2.x ant\u00e9rieures \u00e0 7.2.4","product":{"name":"FortiManager","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiOS versions 7.2.x ant\u00e9rieures \u00e0 7.2.7","product":{"name":"FortiOS","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiPAM 1.2 toutes versions","product":{"name":"FortiPAM","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiProxy 1.0 toutes versions","product":{"name":"FortiProxy","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiClientEMS versions 7.0.x ant\u00e9rieures \u00e0 7.0.11","product":{"name":"FortiClientEMS","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiClientEMS versions 7.2.x ant\u00e9rieures \u00e0 7.2.3","product":{"name":"FortiClientEMS","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiOS 6.0 toutes versions","product":{"name":"FortiOS","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiWeb versions 7.4.x ant\u00e9rieures \u00e0 7.4.3","product":{"name":"FortiWeb","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiClientEMS 6.2 et 6.4 toutes versions","product":{"name":"FortiClientEMS","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiNAC versions 9.4.x ant\u00e9rieures \u00e0 9.4.4","product":{"name":"FortiNAC","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiProxy 7.0 toutes versions","product":{"name":"FortiProxy","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiPAM 1.1 toutes versions","product":{"name":"FortiPAM","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiManager 6.2, 6.4 et 7.0 toutes versions","product":{"name":"FortiManager","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiProxy versions 7.2.x ant\u00e9rieures \u00e0 7.2.9","product":{"name":"FortiProxy","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiAnalyzer-BigData 6.2, 6.4 et 7.0 toutes versions","product":{"name":"FortiAnalyzer","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiProxy versions 2.0.x ant\u00e9rieures \u00e0 2.0.14","product":{"name":"FortiProxy","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiOS versions 6.4.x ant\u00e9rieures \u00e0 6.4.15","product":{"name":"FortiOS","vendor":{"name":"Fortinet","scada":false}}},{"description":"FortiAnalyzer 6.2, 6.4 et 7.0 toutes versions","product":{"name":"FortiAnalyzer","vendor":{"name":"Fortinet","scada":false}}}],"affected_systems_content":null,"content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2023-44487","url":"https://www.cve.org/CVERecord?id=CVE-2023-44487"},{"name":"CVE-2023-45581","url":"https://www.cve.org/CVERecord?id=CVE-2023-45581"},{"name":"CVE-2023-47537","url":"https://www.cve.org/CVERecord?id=CVE-2023-47537"},{"name":"CVE-2024-21762","url":"https://www.cve.org/CVERecord?id=CVE-2024-21762"},{"name":"CVE-2023-26206","url":"https://www.cve.org/CVERecord?id=CVE-2023-26206"},{"name":"CVE-2023-44253","url":"https://www.cve.org/CVERecord?id=CVE-2023-44253"},{"name":"CVE-2024-23113","url":"https://www.cve.org/CVERecord?id=CVE-2024-23113"}],"links":[],"reference":"CERTFR-2024-AVI-0108","revisions":[{"description":"Version initiale","revision_date":"2024-02-09T00:00:00.000000"},{"description":"Ajout des syst\u00e8mes affect\u00e9s","revision_date":"2024-02-15T00:00:00.000000"},{"description":"Ajout des syst\u00e8mes affect\u00e9s","revision_date":"2024-04-10T00:00:00.000000"}],"risks":[{"description":"D\u00e9ni de service \u00e0 distance"},{"description":"Injection de code indirecte \u00e0 distance (XSS)"},{"description":"Ex\u00e9cution de code arbitraire \u00e0 distance"},{"description":"Atteinte \u00e0 l'int\u00e9grit\u00e9 des donn\u00e9es"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans <span\nclass=\"textit\">les produits Fortinet</span>. Certaines d'entre elles\npermettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire\n\u00e0 distance, un d\u00e9ni de service \u00e0 distance et un contournement de la\npolitique de s\u00e9curit\u00e9.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans les produits Fortinet","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-268 du 08 f\u00e9vrier 2024","url":"https://www.fortiguard.com/psirt/FG-IR-23-268"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-301 du 08 f\u00e9vrier 2024","url":"https://www.fortiguard.com/psirt/FG-IR-23-301"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-063 du 08 f\u00e9vrier 2024","url":"https://www.fortiguard.com/psirt/FG-IR-23-063"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-357 du 08 f\u00e9vrier 2024","url":"https://www.fortiguard.com/psirt/FG-IR-23-357"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-23-397 du 08 f\u00e9vrier 2024","url":"https://www.fortiguard.com/psirt/FG-IR-23-397"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-029 du 08 f\u00e9vrier 2024","url":"https://www.fortiguard.com/psirt/FG-IR-24-029"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Fortinet FG-IR-24-015 du 08 f\u00e9vrier 2024","url":"https://www.fortiguard.com/psirt/FG-IR-24-015"}]}
