Critical FortiOS pre-auth RCE vulnerability exploited by attackers (CVE-2022-42475)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-42475 | Unauthenticated Heap Overflow in Fortinet FortiOS/FortiProxy SSL-VPN (Critical RCE) CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow in the SSL-VPN service of Fortinet FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it by sending specifically crafted requests to an exposed SSL-VPN interface, with no user interaction or credentials required. Successful exploitation yields arbitrary code or command execution on the appliance, giving attackers a foothold on the perimeter device from which they can pivot into internal networks. Any organization running the listed FortiOS (6.0 through 7.2) or FortiProxy (7.0/7.2) versions with SSL-VPN enabled is affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, has near-certain exploitation probability (EPSS 99.5%), and has been used in targeted government attacks and a Chinese-nexus espionage campaign that compromised over 20,000 systems, with attackers also noted to retain access even after patching. Do: Upgrade FortiOS and FortiProxy to fixed releases per Fortinet advisory FG-IR-22-398 (any version beyond the listed affected ranges), and reboot the appliance after patching to clear lingering SSL-VPN sessions since attackers have been observed retaining access post-patch. Check for indicators of compromise such as unknown local accounts, unexpected processes, and anomalous historical logins, and rotate SSL-VPN credentials if compromise is suspected. If SSL-VPN is not required, disable it or restrict exposure to trusted sources until patched. | 9.8 | 99% | KEV ransomware PoC |
| masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL-VPN endpoints (well over 100,000; 20,000+ confirmed victims in a single campaign) |
Full article383 words · extracted from helpnetsecurity.com · click to collapse
A critical RCE vulnerability (CVE-2022-42475) in Fortinet’s operating system, FortiOS, is being exploited by attackers, reportedly by a ransomware group.
“Fortinet is aware of an instance where this vulnerability was exploited in the wild,” the company said in an advisory published on Monday, but offered no specific details about the attack.
About CVE-2022-42475
CVE-2022-42475 is a heap-based buffer overflow vulnerability in FortiOS, and “may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests” and, in general, gain full control of vulnerable devices.
FortiOS is based on the Linux kernel and powers many Fortinet’s products, including its FortiGate firewalls. According to Olympe Cyberdefense, this vulnerability specifically affects the operating system’s SSL VPN functionality.
The flaw affects:
- FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, and 6.2.0 through 6.2.11
- FortiOS-6K7K version 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2.0 through 6.2.11, and 6.0.0 through 6.0.14
Fixes and mitigations
FortiOS vulnerabilities are often exploited by attackers.
Fortinet has fixed CVE-2022-42475 in:
- FortiOS version 7.2.3 or above, 7.0.9 or above, 6.4.11 or above, and 6.2.12 or above
- FortiOS-6K7K version 7.0.8 or above, 6.4.10 or above, 6.2.12 or above, and 6.0.15 or above.
As noted by security researcher Will Dormann, some of these were released last month but without any mention of them containing a fix for such a critical zero-day flaw.
Fortinet has not provided any official mitigations for the issue, while Olympe Cyberdefense researchers say disabling the VPN-SSL functionality and setting up conditional access rules can limit organizations’ risk of exploitation.
They also shared some indicators of compromise – log entries and artifacts in the filesystem – that defenders can look for to check whether their devices have been compromised. Fortinet has added to those a few suspicious IP addresses that compromise FortiGate appliances may have contacted.
Freelance IT consultant Ewen McNeill has posited that FortiOS 6.0, which is past its end-of-support date, may be vulnerable as well, and advised users to take precautions.
UPDATE (December 14, 2022, 05:20 a.m. ET):
Fortinet has updated the advisory, confirming that FortiOS 6.0.x and 5.x versions are vulnerable as well. According to McNeill, a FortiOS 6.0.x security fix for this flaw might be in the works.
Fortinet has also confirmed that disabling the SSL-VPN functionality is a possible workaround.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/12/13/cve-2022-42475/