ZeroHour
The Recordpublished ()ingested

Fortinet says VPN bug ‘may have been exploited in a limited number of cases’

criticalRansomwareimportance 60CVE-2023-27997

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27997
Pre-Auth Heap Buffer Overflow RCE in Fortinet FortiOS/FortiProxy SSL-VPN

CVE-2023-27997 is a heap-based buffer overflow (CWE-122, with associated out-of-bounds write CWE-787) in the SSL-VPN component of Fortinet FortiOS and FortiProxy, reachable by unauthenticated users. A remote attacker can trigger it with specially crafted requests to the SSL-VPN web interface, gaining the ability to execute arbitrary code or commands on the gateway. Full control of an edge VPN/firewall appliance enables credential theft, session hijacking, and pivoting into the protected network, which makes the bug attractive to ransomware operators. Any organization exposing the SSL-VPN portal on the affected FortiOS builds (7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below) or FortiProxy builds (7.2.3 and below, 7.0.9 and below, 2.0.12 and below, and 1.1/1.2 all versions) is potentially exposed. The flaw is under active exploitation: CISA added it to the KEV on 2023-06-13 with known ransomware use, EPSS estimates an ~86% probability of exploitation within 30 days (100th percentile), and reporting indicates it was likely being exploited in the wild, with Fortinet also warning that some attackers retained access to FortiGate devices even after patching.

Do: Apply Fortinet's updates to all SSL-VPN-enabled FortiOS and FortiProxy appliances as required by the CISA KEV listing, upgrading each affected branch beyond the listed versions (end-of-life FortiProxy 1.1/1.2 requires migration to a supported release); if SSL-VPN is not needed, disable the web portal or restrict it to trusted source addresses. After patching, hunt for signs of compromise and rotate credentials and VPN-related secrets, since Fortinet warned that some attackers retained access to FortiGate devices post-patching.

9.886% KEV ransomware
  • Fortinet FortiOS (SSL-VPN) 7.2.4 and below; 7.0.11 and below; 6.4.12 and below; 6.0.16 and below
  • Fortinet FortiProxy (SSL-VPN) 7.2.3 and below; 7.0.9 and below; 2.0.12 and below; 1.2 (all versions); 1.1 (all versions)
masson the order of several hundred thousand internet-exposed SSL-VPN endpoints (≈300k–500k per public scans)
Full article634 words · extracted from therecord.media · click to collapse

Network security company Fortinet said a new vulnerability affecting its VPN tool may have already been exploited “in a limited number of cases.”

Concerns about the issue — tracked as CVE-2023-27997 — grew over the weekend due to how widely used Fortinet’s SSL-VPN product is among government organizations.

The bug allows hackers to run unauthorized code or commands remotely on the affected system. Fortinet fixed the issue in an update released last week.

In a blog on Monday, Fortinet said it was notified of the issue by Lexfo Security vulnerability researchers Charles Fol and Dany Bach, but added that the company’s own audit of the SSL-VPN product also uncovered the same vulnerability.

“This audit, together with a responsible disclosure from a third-party researcher, led to the identification of certain issues that have been remediated in the current firmware releases,” the company said.

“Our investigation found that one issue [CVE-2023-27997] may have been exploited in a limited number of cases and we are working closely with customers to monitor the situation.”

In a statement to Recorded Future News, the company reiterated that its been “proactively communicating” with customers and “strongly urging them to immediately follow the guidance provided to mitigate the vulnerability using either the provided workarounds or by upgrading.”

Fortinet said that the hacking campaign was “targeted at government, manufacturing, and critical infrastructure.” The company also dispelled concerns that the vulnerability was being exploited by Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering.

Christopher Glyer of the Microsoft Threat Intelligence Center questioned on Sunday whether the vulnerability was used in the headline-grabbing attacks by Volt Typhoon on critical infrastructure in Guam that were unveiled last month.

Fortinet addressed the theory in its blog, writing that it is not currently linking the vulnerability to the Volt Typhoon campaign but “expects all threat actors, including those behind the Volt Typhoon campaign, to continue to exploit unpatched vulnerabilities in widely used software and devices.”

The New York Times reported that the infrastructure compromised by the Chinese group included the telecommunications network of Guam, a U.S. territory in the Pacific Ocean described by the Department of Defense as “a strategic hub supporting crucial operations and logistics for all U.S. forces operating in the Indo-Pacific region.”

The cybersecurity agencies of the U.S., Australia and New Zealand released advisories about the issue on Monday, warning organizations to immediately apply the patch. The Cybersecurity and Infrastructure Security Agency added the vulnerability to its catalog of exploited vulnerabilities on Tuesday.

A patch for the issue was included in FortiOS firmware versions 6.0.17, 6.2.15, 6.4.13, 7.0.12, and 7.2.5.

Tenable’s Satnam Narang told Recorded Future News that over the past five years, there has been a persistent trend of vulnerabilities in SSL VPN products such as those from Citrix, Pulse Secure and Fortinet being targeted.

“These flaws have not only been exploited by ransomware groups but also by nation-state aligned threat actors with a particular focus on flaws in Fortinet devices. SSL-VPNs are attractive targets due to their internet-facing nature, providing access to a company’s intranet,” he said.

“They became even more popular at the beginning of the pandemic, as organization’s shifted towards allowing for remote work. Pre-authentication flaws are especially valuable to a remote attacker, because it doesn’t require them to already have valid credentials.”

Narang warned that once a proof-of-concept exploit for this flaw is made public, defenders should expect more widespread scanning and exploitation of vulnerable assets.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/fortinet-vulnerability-possible-exploitation-ssl-vpn