New Fortinet's FortiNAC Vulnerability Exposes Networks to Code Execution Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-39952 | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6 A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request. NVD description · AI analysis pending | 9.8 | 100% |
| — | ||
| CVE-2023-27997 | Pre-Auth Heap Buffer Overflow RCE in Fortinet FortiOS/FortiProxy SSL-VPN CVE-2023-27997 is a heap-based buffer overflow (CWE-122, with associated out-of-bounds write CWE-787) in the SSL-VPN component of Fortinet FortiOS and FortiProxy, reachable by unauthenticated users. A remote attacker can trigger it with specially crafted requests to the SSL-VPN web interface, gaining the ability to execute arbitrary code or commands on the gateway. Full control of an edge VPN/firewall appliance enables credential theft, session hijacking, and pivoting into the protected network, which makes the bug attractive to ransomware operators. Any organization exposing the SSL-VPN portal on the affected FortiOS builds (7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below) or FortiProxy builds (7.2.3 and below, 7.0.9 and below, 2.0.12 and below, and 1.1/1.2 all versions) is potentially exposed. The flaw is under active exploitation: CISA added it to the KEV on 2023-06-13 with known ransomware use, EPSS estimates an ~86% probability of exploitation within 30 days (100th percentile), and reporting indicates it was likely being exploited in the wild, with Fortinet also warning that some attackers retained access to FortiGate devices even after patching. Do: Apply Fortinet's updates to all SSL-VPN-enabled FortiOS and FortiProxy appliances as required by the CISA KEV listing, upgrading each affected branch beyond the listed versions (end-of-life FortiProxy 1.1/1.2 requires migration to a supported release); if SSL-VPN is not needed, disable the web portal or restrict it to trusted source addresses. After patching, hunt for signs of compromise and rotate credentials and VPN-related secrets, since Fortinet warned that some attackers retained access to FortiGate devices post-patching. | 9.8 | 86% | KEV ransomware |
| masson the order of several hundred thousand internet-exposed SSL-VPN endpoints (≈300k–500k per public scans) | |
| CVE-2023-3128 | Grafana is validating Azure AD accounts based on the email claim. Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app. NVD description · AI analysis pending | 9.8 | 4% |
| — | ||
| CVE-2023-33299 | A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauth A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x will not be fixed. NVD description · AI analysis pending | 9.8 | 24% |
| — | ||
| CVE-2023-33300 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication port. NVD description · AI analysis pending | 5.3 | 14% |
| — |
Full article444 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 27, 2023Vulnerability / Exploit
Fortinet has rolled out updates to address a critical security vulnerability impacting its FortiNAC network access control solution that could lead to the execution of arbitrary code.
Tracked as CVE-2023-33299, the flaw is rated 9.6 out of 10 for severity on the CVSS scoring system. It has been described as a case of Java untrusted object deserialization.
"A deserialization of untrusted data vulnerability [CWE-502] in FortiNAC may allow an unauthenticated user to execute unauthorized code or commands via specifically crafted requests to the tcp/1050 service," Fortinet said in an advisory published last week.
The shortcoming impacts the following products, with patches available in FortiNAC versions 7.2.2, 9.1.10, 9.2.8, and 9.4.3 or later -
- FortiNAC version 9.4.0 through 9.4.2
- FortiNAC version 9.2.0 through 9.2.7
- FortiNAC version 9.1.0 through 9.1.9
- FortiNAC version 7.2.0 through 7.2.1
- FortiNAC 8.8 all versions
- FortiNAC 8.7 all versions
- FortiNAC 8.6 all versions
- FortiNAC 8.5 all versions, and
- FortiNAC 8.3 all versions
Also resolved by Fortinet is a medium-severity vulnerability tracked as CVE-2023-33300 (CVSS score: 4.8), an improper access control issue affecting FortiNAC 9.4.0 through 9.4.3 and FortiNAC 7.2.0 through 7.2.1. It has been fixed in FortiNAC versions 7.2.2 and 9.4.4.
Florian Hauser from German cybersecurity firm CODE WHITE has been credited with discovering and reporting the two bugs.
The alert follows the active exploitation of another critical vulnerability affecting FortiOS and FortiProxy (CVE-2023-27997, CVSS score: 9.2) that could allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.
Fortinet, earlier this month, acknowledged that the issue may have been abused in limited attacks targeting government, manufacturing, and critical infrastructure sectors, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to the Known Exploited Vulnerabilities (KEV) catalog.
It also comes more than four months after Fortinet addressed a severe bug in FortiNAC (CVE-2022-39952, CVSS score: 9.8) that could lead to arbitrary code execution. The flaw has since come under active exploitation shortly after a proof-of-concept (PoC) was made available.
In a related development, Grafana has released patches for a critical security vulnerability (CVE-2023-3128) that could permit malicious attackers to bypass authentication and take over any account that uses Azure Active Directory for authentication.
"If exploited, the attacker can gain complete control of a user's account, including access to private customer data and sensitive information," Grafana said. "If exploited, the attacker can gain complete control of a user's account, including access to private customer data and sensitive information."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/06/new-fortinets-fortinac-vulnerability.html