ZeroHour
Recorded Futurepublished ()ingested German Hoeffner, Aaron Soehnen & Gianni Perez1

CVE-2022-42475: Fortinet Pre-authentication Code-execution Vulnerability

criticalVulnerability exploited in the wildimportance 60CVE-2022-42475

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-42475
Unauthenticated Heap Overflow in Fortinet FortiOS/FortiProxy SSL-VPN (Critical RCE)

CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow in the SSL-VPN service of Fortinet FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it by sending specifically crafted requests to an exposed SSL-VPN interface, with no user interaction or credentials required. Successful exploitation yields arbitrary code or command execution on the appliance, giving attackers a foothold on the perimeter device from which they can pivot into internal networks. Any organization running the listed FortiOS (6.0 through 7.2) or FortiProxy (7.0/7.2) versions with SSL-VPN enabled is affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, has near-certain exploitation probability (EPSS 99.5%), and has been used in targeted government attacks and a Chinese-nexus espionage campaign that compromised over 20,000 systems, with attackers also noted to retain access even after patching.

Do: Upgrade FortiOS and FortiProxy to fixed releases per Fortinet advisory FG-IR-22-398 (any version beyond the listed affected ranges), and reboot the appliance after patching to clear lingering SSL-VPN sessions since attackers have been observed retaining access post-patch. Check for indicators of compromise such as unknown local accounts, unexpected processes, and anomalous historical logins, and rotate SSL-VPN credentials if compromise is suspected. If SSL-VPN is not required, disable it or restrict exposure to trusted sources until patched.

9.899% KEV ransomware PoC
  • Fortinet FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, and 6.0.15 and earlier
  • Fortinet FortiProxy SSL-VPN 7.2.0 through 7.2.1, and 7.0.7 and earlier
masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL-VPN endpoints (well over 100,000; 20,000+ confirmed victims in a single campaign)
Full article454 words · extracted from recordedfuture.com · click to collapse

Fortinet continues to garner and release information to address a recently-discovered heap-based buffer overflow vulnerability impacting several versions of FortiOS (FOS), the operating system behind an entire series of FortiGate next-generation firewalls and security appliances.

This new vulnerability comes on the heels of a very recent one whereby an alternate path or channel could allow threat actors to perform authentication bypasses and subsequent administrative operations on a handful of FOS, FortiProxy, and FortiSwitchManager endpoints.

In its latest PSIRT advisory, the company further provides a set of various indicators of compromise—these include the presence of file system artifacts and similar log entries as a sign of exploitation. Officially listed as CVE-2022-42475, this latest zero-day is classified as critical with a CVSS score of 9.3.

What’s Fortigate VPN?

Fortinet provides the foundation for enterprise-class security through a multitude of services that include an array of VPN solutions designed to deliver secure, non-uniform, and reliable information transfer across networks.

Impact and Affected Version

According to the advisory, these are the affected versions and fixes:

  • FortiOS 7.2.0 to 7.2.2 - fixed in 7.2.3
  • FortiOS 7.0.0 to 7.0.8 - fixed in 7.0.9
  • FortiOS 6.4.0 to 6.4.10 - fixed in 6.4.11
  • FortiOS 6.2.0 to 6.2.11 - fixed in 6.2.12
  • FortiOS 6.0.0 to 6.0.15 - fixed in 6.0.16 (upcoming)
  • FortiOS 5.x.x - upgrade to 6.0.16 and above
  • FortiOS-6K7K 7.0.0 to 7.0.7 - fixed in 7.0.8 (upcoming)
  • FortiOS-6K7K 6.4.0 to 6.4.9 - fixed in 6.4.10
  • FortiOS-6K7K 6.2.0 to 6.2.11 - fixed in 6.2.12 (upcoming)
  • FortiOS-6K7K 6.0.0 to 6.0.14 - fixed in 6.0.15

Any customers running FortiOS 6.2, or earlier, are strongly advised to upgrade to the latest version, given an “end of engineering support” policy from March 2022 and an upcoming “end of support” one due September 2023.

How to mitigate/patch this vulnerability

As of today, upgrading to a fixed version (mainly 7.2.3 or 7.0.9) is the only way to patch this vulnerability. Firmware updates, however, are only available in the customer portal with an active support contract.

Customers must also be made aware that intermediary version upgrades might be needed for larger version jumps. (Fortinet has provided an upgrade tool for this purpose.) If updates are not an option, the SSL-VPN functionality can also be disabled as a temporary workaround.

Summary

At the time of this writing, the Recorded Future Attack Surface Intelligence platform can detect the underlying Fortinet product and hostnames, but not the exact impacted FOS version, so a manual investigation will still be required to look for indicators of compromise.

As Fortinet is aware of at least one case of active exploitation, the company urges its customers to take immediate action in applying all pertinent fixes. We will release new updates as soon as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/cve-2022-42475-fortinet-pre-authentication-code-execution-vuln