<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Fortigate - Fix Bilişim Teknolojileri</title>
	<atom:link href="https://www.fixbilisim.com.tr/tag/fortigate/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.fixbilisim.com.tr</link>
	<description>Fix Bilişim, müşteri odaklı hizmet anlayışı ve &#34;mevcut koşullar altında mümkün olan en iyisi&#34; felsefesi ile sizleri tekrar çözüm ortağı aramak durumunda bırakmaz.</description>
	<lastBuildDate>Tue, 13 Dec 2022 09:40:13 +0000</lastBuildDate>
	<language>tr</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.fixbilisim.com.tr/wp-content/uploads/2021/03/amblem-150x150.png</url>
	<title>Fortigate - Fix Bilişim Teknolojileri</title>
	<link>https://www.fixbilisim.com.tr</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Fortigate, Kritik Güvenlik Açığı</title>
		<link>https://www.fixbilisim.com.tr/cve-2022-42475-fortigate-sslvpn-guvenlik-acigi/</link>
					<comments>https://www.fixbilisim.com.tr/cve-2022-42475-fortigate-sslvpn-guvenlik-acigi/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 13 Dec 2022 09:22:40 +0000</pubDate>
				<category><![CDATA[Siber Güvenlik]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Güvenlik Açığı]]></category>
		<guid isPermaLink="false">https://www.fixbilisim.com.tr/?p=2231</guid>

					<description><![CDATA[<p>CVE-2022-42475 Fortigate SSLVPN Güvenlik Açığı üzerinden, saldırganlar alternatif kimlik doğrulama yöntemleri ile sisteminizde kod çalıştırabilir. Kimliği doğrulanmamış uzak bir saldırganın özel olarak hazırlanmış istekler aracılığıyla rastgele kod veya komutlar yürütmesine izin verebilir. Fortinet, bu güvenlik açığından kaynaklanan güvenlik zafiyetinin farkındadır ve sistemlerinizi aşağıdaki tehlike göstergelerine karşı derhal güncellemenizi önerir Tespit edilen log kayıtları : Logdesc="Application</p>
<p>The post <a href="https://www.fixbilisim.com.tr/cve-2022-42475-fortigate-sslvpn-guvenlik-acigi/">Fortigate, Kritik Güvenlik Açığı</a> first appeared on <a href="https://www.fixbilisim.com.tr">Fix Bilişim Teknolojileri</a>.</p>]]></description>
										<content:encoded><![CDATA[<div data-elementor-type="wp-post" data-elementor-id="2231" class="elementor elementor-2231" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-37f7f5a elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="37f7f5a" data-element_type="section">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-9f82b57" data-id="9f82b57" data-element_type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-d1af01a elementor-widget elementor-widget-image" data-id="d1af01a" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
													<img fetchpriority="high" decoding="async" width="640" height="363" src="https://www.fixbilisim.com.tr/wp-content/uploads/2022/11/SNWL-image-414-copy-1024x580.jpg" class="attachment-large size-large wp-image-1948" alt="" srcset="https://www.fixbilisim.com.tr/wp-content/uploads/2022/11/SNWL-image-414-copy-1024x580.jpg 1024w, https://www.fixbilisim.com.tr/wp-content/uploads/2022/11/SNWL-image-414-copy-300x170.jpg 300w, https://www.fixbilisim.com.tr/wp-content/uploads/2022/11/SNWL-image-414-copy-768x435.jpg 768w, https://www.fixbilisim.com.tr/wp-content/uploads/2022/11/SNWL-image-414-copy-1536x871.jpg 1536w, https://www.fixbilisim.com.tr/wp-content/uploads/2022/11/SNWL-image-414-copy.jpg 1632w" sizes="(max-width: 640px) 100vw, 640px" />													</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				<section class="elementor-section elementor-top-section elementor-element elementor-element-3cc4af6 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="3cc4af6" data-element_type="section">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4c51bf94" data-id="4c51bf94" data-element_type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-4dd47b7a elementor-widget elementor-widget-text-editor" data-id="4dd47b7a" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
							CVE-2022-42475 Fortigate SSLVPN Güvenlik Açığı üzerinden, saldırganlar alternatif kimlik doğrulama yöntemleri ile sisteminizde kod çalıştırabilir.

Kimliği doğrulanmamış uzak bir saldırganın özel olarak hazırlanmış istekler aracılığıyla rastgele kod veya komutlar yürütmesine izin verebilir.

Fortinet, bu güvenlik açığından kaynaklanan güvenlik zafiyetinin farkındadır ve sistemlerinizi aşağıdaki tehlike göstergelerine karşı derhal güncellemenizi önerir

Tespit edilen log kayıtları :

<code><tt>Logdesc="Application crashed" and msg="[...] application:sslvpnd,[...], Signal 11 received, Backtrace: [...]“</tt></code>

Dosya sisteminde tespit edilen zafiyetler:

<code>/data/lib/libips.bak
/data/lib/libgif.so
/data/lib/libiptcp.so
/data/lib/libipudp.so
/data/lib/libjepg.so
/var/.sslvpnconfigbk
/data/etc/wxd.conf
/flash</code>

Fortigate&#8217;in tesis ettiği şüpheli bağlantılar:

<code>188.34.130.40:444
103.131.189.143:30080,30081,30443,20443
192.36.119.61:8443,444
172.247.168.153:8033</code>
<h3><strong>Etkilenen Ürünler :</strong></h3>
<div class="detail-item" lang="en">

FortiOS version 7.2.0 through 7.2.2
FortiOS version 7.0.0 through 7.0.8
FortiOS version 6.4.0 through 6.4.10
FortiOS version 6.2.0 through 6.2.11
FortiOS-6K7K version 7.0.0 through 7.0.7
FortiOS-6K7K version 6.4.0 through 6.4.9
FortiOS-6K7K version 6.2.0 through 6.2.11
FortiOS-6K7K version 6.0.0 through 6.0.14

</div>
<div class="detail-item" lang="en">
<h3>Çözüm :</h3>
Please upgrade to FortiOS version 7.2.3 or above
Please upgrade to FortiOS version 7.0.9 or above
Please upgrade to FortiOS version 6.4.11 or above
Please upgrade to FortiOS version 6.2.12 or above
Please upgrade to FortiOS-6K7K version 7.0.8 or above
Please upgrade to FortiOS-6K7K version 6.4.10 or above
Please upgrade to FortiOS-6K7K version 6.2.12 or above
Please upgrade to FortiOS-6K7K version 6.0.15 or above

</div>
Kaynak: https://www.fortiguard.com/psirt/FG-IR-22-398						</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				<section class="elementor-section elementor-top-section elementor-element elementor-element-3822896 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="3822896" data-element_type="section">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0c90bf9" data-id="0c90bf9" data-element_type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-d8ad80e elementor-share-buttons--view-icon-text elementor-share-buttons--skin-gradient elementor-share-buttons--shape-square elementor-grid-0 elementor-share-buttons--color-official elementor-widget elementor-widget-share-buttons" data-id="d8ad80e" data-element_type="widget" data-widget_type="share-buttons.default">
				<div class="elementor-widget-container">
					<div class="elementor-grid">
								<div class="elementor-grid-item">
						<div
							class="elementor-share-btn elementor-share-btn_facebook"
							role="button"
							tabindex="0"
							aria-label="Share on facebook">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-facebook" aria-hidden="true"></i>							</span>
																						<div class="elementor-share-btn__text">
																			<span class="elementor-share-btn__title">
										Facebook									</span>
																	</div>
													</div>
					</div>
									<div class="elementor-grid-item">
						<div
							class="elementor-share-btn elementor-share-btn_twitter"
							role="button"
							tabindex="0"
							aria-label="Share on twitter">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-twitter" aria-hidden="true"></i>							</span>
																						<div class="elementor-share-btn__text">
																			<span class="elementor-share-btn__title">
										Twitter									</span>
																	</div>
													</div>
					</div>
									<div class="elementor-grid-item">
						<div
							class="elementor-share-btn elementor-share-btn_linkedin"
							role="button"
							tabindex="0"
							aria-label="Share on linkedin">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-linkedin" aria-hidden="true"></i>							</span>
																						<div class="elementor-share-btn__text">
																			<span class="elementor-share-btn__title">
										LinkedIn									</span>
																	</div>
													</div>
					</div>
						</div>
				</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div><p>The post <a href="https://www.fixbilisim.com.tr/cve-2022-42475-fortigate-sslvpn-guvenlik-acigi/">Fortigate, Kritik Güvenlik Açığı</a> first appeared on <a href="https://www.fixbilisim.com.tr">Fix Bilişim Teknolojileri</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.fixbilisim.com.tr/cve-2022-42475-fortigate-sslvpn-guvenlik-acigi/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
