Fortinet warns of hackers targeting governments through VPN vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-42475 | Unauthenticated Heap Overflow in Fortinet FortiOS/FortiProxy SSL-VPN (Critical RCE) CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow in the SSL-VPN service of Fortinet FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it by sending specifically crafted requests to an exposed SSL-VPN interface, with no user interaction or credentials required. Successful exploitation yields arbitrary code or command execution on the appliance, giving attackers a foothold on the perimeter device from which they can pivot into internal networks. Any organization running the listed FortiOS (6.0 through 7.2) or FortiProxy (7.0/7.2) versions with SSL-VPN enabled is affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, has near-certain exploitation probability (EPSS 99.5%), and has been used in targeted government attacks and a Chinese-nexus espionage campaign that compromised over 20,000 systems, with attackers also noted to retain access even after patching. Do: Upgrade FortiOS and FortiProxy to fixed releases per Fortinet advisory FG-IR-22-398 (any version beyond the listed affected ranges), and reboot the appliance after patching to clear lingering SSL-VPN sessions since attackers have been observed retaining access post-patch. Check for indicators of compromise such as unknown local accounts, unexpected processes, and anomalous historical logins, and rotate SSL-VPN credentials if compromise is suspected. If SSL-VPN is not required, disable it or restrict exposure to trusted sources until patched. | 9.8 | 99% | KEV ransomware PoC |
| masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL-VPN endpoints (well over 100,000; 20,000+ confirmed victims in a single campaign) |
Full article490 words · extracted from therecord.media · click to collapse
Fortinet published an advisory this week warning that a critical vulnerability is being exploited by an “advanced actor” to target government networks. Fortinet published an advisory about the bug – CVE-2022-42475 – and it quickly garnered widespread attention due to its 9.8 CVSS score, ease of use and the large number of FortiOS versions affected. French security firm Olympe was the first to spot the bug in the wild and Fortinet patched the issue just three days later. Cybersecurity researcher Kevin Beaumont said the bug was being used by ransomware groups. The Cybersecurity and Infrastructure Security Agency (CISA) published its own advisory about the issue on December 12 urging administrators to look through Fortinet’s advisory. CISA said an attacker could exploit the vulnerability “to take control of an affected system” and said the vulnerability was already being exploited. This week, Fortinet released an examination of an exploit for the bug and said the complexity of it “suggests an advanced actor and that it is highly targeted at governmental or government-related targets.” The company said it got a sample of the malware – which was a variant of a generic Linux implant customized for FortiOS. “The exploit requires a deep understanding of FortiOS and the underlying hardware. The use of custom implants shows that the actor has advanced capabilities, including reverse-engineering various parts of FortiOS. The actor is highly targeted, with some hints of preferred governmental or government-related targets,” Fortinet said. “The discovered Windows sample attributed to the attacker displayed artifacts of having been compiled on a machine in the UTC+8 timezone, which includes Australia, China, Russia, Singapore, and other Eastern Asian countries.” Tenable’s Claire Tills said the critical flaw is a buffer overflow vulnerability – which involves overloading a buffer with more data than it can handle, causing a crash or creating an entry point for attacks. Tills explained that CVE-2022-42475 could lead to remote code execution in several versions of FortiOS used in SSL-VPNs and firewalls. “Fortinet SSL-VPNs have been a major target for years now — to the extent that the FBI and CISA issued a dedicated advisory to these flaws and their exploitation in 2021,” she said, referencing several alerts from the FBI and CISA about government hackers using FortiOS vulnerabilities. “Nation state actors are still known to exploit those legacy vulnerabilities in Fortinet SSL-VPNs. Given that this new vulnerability has already been exploited, organizations should patch CVE-2022-42475 immediately before it joins the ranks of other legacy VPN flaws.” In 2021, Fortinet also said a cybercriminal gang managed to obtain a collection of access credentials for more than 87,000 FortiGate SSL-VPN devices.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/fortinet-warns-of-hackers-targeting-governments-through-vpn-vulnerability