QID 375929
Date Published: 2021-10-29
QID 375929: Fortinet FortiManager VM Multiple Vulnerabilities (FG-IR-19-017)
FortiManager provides centralized policy-based provisioning, device configuration, and update management for for FortiGate, FortiWiFi, and FortiMail appliances, and FortiClient end-point security agents, plus end-to-end network monitoring and device control.
Affected Products:
FortiManager VM version 6.2.0, 6.0.6 and below
Fixed Products:
Upgrade to FortiManager VM versions 6.0.7 or 6.2.1
Detection Login(Authenticated)
QID will fire the command get system status and will match the affected version.
Note: we do not have support for FortiOS VM for now.
Lack of root file system integrity checking in Fortinet FortiManager VM application images may allow an attacker to implant third-party programs by recreating the image through specific methods.
Workaround:
Verify the integrity of VM images by comparing the SHA-512 checksum with the checksum indicated on downloads section for that image.
- FG-IR-19-017 -
www.fortiguard.com/psirt/FG-IR-19-017
CVEs related to QID 375929
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-19-017 |
|