FG-IR-23-008: SSH key is added even if operation is aborted
An incomplete cleanup vulnerability [CWE-459] in FortiOS & FortiProxy may allow a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-008?
The severity of FG-IR-23-008 is critical due to the potential unauthorized access enabled by the incomplete cleanup vulnerability.
How do I fix FG-IR-23-008?
To fix FG-IR-23-008, upgrade FortiOS and FortiProxy to the recommended versions which are 7.2.3 or 7.0.9 respectively.
Who is affected by FG-IR-23-008?
FG-IR-23-008 affects VDOM privileged users on FortiOS and FortiProxy versions before the specified remedied updates.
What type of vulnerability is FG-IR-23-008?
FG-IR-23-008 is classified as an incomplete cleanup vulnerability, specifically categorized under CWE-459.
Can FG-IR-23-008 lead to system compromise?
Yes, FG-IR-23-008 can lead to system compromise allowing attackers to silently add SSH key files via crafted commands.