Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ialhusari93
New Contributor II

CVE-2022-42475 SSLVPN FortiGate 100E from 6.4.8 to 6.4.11

Dears , 

 

are there any concerns to upgrade fortios from 6.4.8 to 6.4.11 so we can use ssl vpn again   ?

 

Regards 

 

1 Solution
pgautam
Staff
Staff

Dear Customer,

 

Please check the PSIRT advisory for the CVE ID CVE-2022-42475

https://www.fortiguard.com/psirt/FG-IR-22-398

 

Please check the release note of 6.4.11 and follow the upgrade path using the upgrade path tool

 

https://docs.fortinet.com/upgrade-tool 

 

https://docs.fortinet.com/document/fortigate/6.4.11/fortios-release-notes/289806/resolved-issues

853448

FortiOS 6.4.11 is no longer vulnerable to the following CVE Reference:

  • CVE-2022-42475

 

Regards 

Priyanka 

View solution in original post

2 REPLIES 2
pgautam
Staff
Staff

Dear Customer,

 

Please check the PSIRT advisory for the CVE ID CVE-2022-42475

https://www.fortiguard.com/psirt/FG-IR-22-398

 

Please check the release note of 6.4.11 and follow the upgrade path using the upgrade path tool

 

https://docs.fortinet.com/upgrade-tool 

 

https://docs.fortinet.com/document/fortigate/6.4.11/fortios-release-notes/289806/resolved-issues

853448

FortiOS 6.4.11 is no longer vulnerable to the following CVE Reference:

  • CVE-2022-42475

 

Regards 

Priyanka 

ede_pfau
Esteemed Contributor III

Recommended upgrade path is

6.4.8 -> 6.4.9 -> 6.4.11

 

Had to upgrade quite a couple of FGTs, so I looked it up.

Not following the recommended upgrade path may result in parts of the config not being translated, an thus lost.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors