Skip to main content
Assiamour_
Explorer
April 2, 2024
Solved

Fortianalyzer Critical Vulnerability CVE-2023-28531 OpenSSH

  • April 2, 2024
  • 6 replies
  • 10284 views

Our tenable is detecting that our Fortianalyzer VM is using a vulnerable version of openSSH " The version of OpenSSH installed on the remote host is prior to 9.3 " and we should upgrade to a 9.3 or later. 

is there any patch for that?

 

image.png

Best answer by jasonhong

FortiAnalyzer is not considered vulnerable to CVE-2023-28531 because it does not use ssh-add, nor smartcard, nor ssh-agent.

6 replies

AEK
SuperUser
SuperUser
April 2, 2024

Which FAZ version? 

AEK
Assiamour_
Explorer
April 2, 2024

the Faz is running on the latest version: v7.4.2-build2397

AEK
SuperUser
SuperUser
April 2, 2024

Can you try exploit the vulnerability?

The idea behind is, I think it is possible that the OpenSSH version on your FAZ is a modified version (by Fortinet).

AEK
jasonhong
Staff & Editor
jasonhongAnswer
Staff & Editor
April 3, 2024

FortiAnalyzer is not considered vulnerable to CVE-2023-28531 because it does not use ssh-add, nor smartcard, nor ssh-agent.

Assiamour_
Explorer
April 3, 2024

Thank you for your answer. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.