ZeroHour

CVE-2021-44168

KEVmass

Local Arbitrary File Download Flaw in Fortinet FortiOS 'execute restore src-vis'

CISA: Fortinet FortiOS Arbitrary File Download

CVSS 3.1
7.8 high
EPSS
<1%p57
Published
()
KEV added
AI analysis

CVE-2021-44168 is a download-of-code-without-integrity-check vulnerability (CWE-494) in the "execute restore src-vis" command of Fortinet FortiOS. A local, authenticated attacker who can invoke this command can supply a specially crafted update package that the device processes without verifying its integrity, allowing arbitrary files to be downloaded on the device. Per the CVSS 3.1 score of 7.8 (AV:L/AC:L/PR:L), the local privileges and crafted package are the only prerequisites, and the potential impact is high for confidentiality, integrity, and availability. Any organization running FortiOS versions before 7.0.3 is affected. The flaw is confirmed to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2021-12-10 (the same catalog update that added Log4Shell), though no public proof-of-concept is known, EPSS is 0.9%, and ransomware use is unknown.

What to do: Upgrade FortiOS to 7.0.3 or later per Fortinet's vendor instructions, as required by the CISA KEV listing. Until patched, restrict local/CLI administrative access to trusted operators, since exploitation requires an authenticated local session, and monitor for use of the "execute restore src-vis" command with untrusted or unexpected packages.

Affected
Fortinet FortiOSbefore 7.0.3
Estimated exposure
massmillions of FortiGate/FortiOS installations worldwide — Fortinet is one of the largest edge firewall vendors, with millions of FortiGate units shipped and hundreds of thousands of FortiGate management/SSL-VPN interfaces observed in public internet scans, so deployments on versions prior to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

CISA Known Exploited Vulnerability
Affected
Fortinet FortiOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
fortinet
Products
fortios
Weakness
CWE-494
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news