Information security company Fortinet patched major vulnerabilities CVE-2022-39952 and CVE-2021-42756 this week. These vulnerabilities are respectively related to the brand’s network access control system (NAC) and web application firewall (WAF). The point is that attackers can exploit it without being authenticated. The researchers disclosed the vulnerabilities CVE-2022-45788 and CVE-2022-45789 in Schneider Electric PLC, and pointed out that these vulnerabilities can be chained and exploited to allow attackers to remotely execute arbitrary code (RCE). The recent attacks of the malware FatalRAT are also noteworthy. Although hackers mainly target users who use Simplified Chinese, there are also victims in Taiwan.
![[Information Security Daily]On February 18, 2023, Fortinet patched major vulnerabilities in WAF and network access control systems, Schneider Electric PLC has vulnerabilities that can be used for RCE attacks 1 20230218](https://mlmanfsmq3vm.i.optimole.com/w:1280/h:560/q:mauto/rt:fill/g:sm/f:avif/https://urbantechstory.com/wp-content/uploads/2023/02/20230218.png)