FortiOS - FG-IR-22-398 vulnerability
Incident Report for Ekco Cloud Edinburgh
Update
Please note that the list of affected FortiOS versions has been revised as per the below.

Affected products are as follows:

FortiOS version 7.2.0 through 7.2.2
FortiOS version 7.0.0 through 7.0.8
FortiOS version 6.4.0 through 6.4.10
FortiOS version 6.2.0 through 6.2.11
FortiOS version 6.0.0 through 6.0.15
FortiOS version 5.6.0 through 5.6.14
FortiOS version 5.4.0 through 5.4.13
FortiOS version 5.2.0 through 5.2.15
FortiOS version 5.0.0 through 5.0.14
FortiOS-6K7K version 7.0.0 through 7.0.7
FortiOS-6K7K version 6.4.0 through 6.4.9
FortiOS-6K7K version 6.2.0 through 6.2.11
FortiOS-6K7K version 6.0.0 through 6.0.14

Solutions are as follows:

Please upgrade to FortiOS version 7.2.3 or above
Please upgrade to FortiOS version 7.0.9 or above
Please upgrade to FortiOS version 6.4.11 or above
Please upgrade to FortiOS version 6.2.12 or above
Please upgrade to upcoming FortiOS version 6.0.16 or above
Please upgrade to upcoming FortiOS-6K7K version 7.0.8 or above
Please upgrade to FortiOS-6K7K version 6.4.10 or above
Please upgrade to upcoming FortiOS-6K7K version 6.2.12 or above
Please upgrade to FortiOS-6K7K version 6.0.15 or above
Posted Dec 14, 2022 - 14:35 GMT
Identified
For all customers who subscribe to a Managed Firewall service, Ekco will be in contact to arrange a firmware upgrade, should this be required.

For any customers that manage their own FortiGate firewalls and their upgrades, please note the following:

Affected products are as follows:

FortiOS version 7.2.0 through 7.2.2
FortiOS version 7.0.0 through 7.0.8
FortiOS version 6.4.0 through 6.4.10
FortiOS version 6.2.0 through 6.2.11
FortiOS-6K7K version 7.0.0 through 7.0.7
FortiOS-6K7K version 6.4.0 through 6.4.9
FortiOS-6K7K version 6.2.0 through 6.2.11
FortiOS-6K7K version 6.0.0 through 6.0.14

Solutions are as follows:

Please upgrade to FortiOS version 7.2.3 or above
Please upgrade to FortiOS version 7.0.9 or above
Please upgrade to FortiOS version 6.4.11 or above
Please upgrade to FortiOS version 6.2.12 or above
Please upgrade to FortiOS-6K7K version 7.0.8 or above
Please upgrade to FortiOS-6K7K version 6.4.10 or above
Please upgrade to FortiOS-6K7K version 6.2.12 or above
Please upgrade to FortiOS-6K7K version 6.0.15 or above

Should you have any questions or concerns, please reach out to Ekco Support via support@ek.co or call +44 1273 987 920.
Posted Dec 12, 2022 - 23:23 GMT
Investigating
Ekco have been made aware of the following issue with Forti OS https://fortiguard.fortinet.com/psirt/FG-IR-22-398 we are investigating the issue as a matter of urgency and will be contacting customers to advise what action to take.
Posted Dec 12, 2022 - 20:36 GMT
This incident affects: Cloud (Compute).