Fortinet CVE-2023
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-40684 | Admin-Interface Auth Bypass in Fortinet FortiOS, FortiProxy & FortiSwitchManager Fortinet's FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability (CWE-288) that lets an unauthenticated remote attacker gain access to the administrative interface. It is triggered by sending specially crafted HTTP or HTTPS requests directly to the admin interface, with no credentials or exploit code required. By bypassing authentication, an attacker can perform administrative operations on the device, such as modifying configuration or creating privileged accounts. Any organization running the affected products is exposed, particularly where the management interface is reachable from the internet. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 with known ransomware use, and EPSS assigns it roughly a 100% probability of exploitation within 30 days, although no public PoC is known. Do: Upgrade FortiOS, FortiProxy, and FortiSwitchManager to the fixed releases identified in Fortinet's advisory per the KEV required action. As mitigation, restrict access to the admin interface (e.g., disable WAN-facing management and use local-in policies or allow-lists for management IPs). Review admin logs and device configuration for signs of unauthorized access, such as unexpected admin accounts, added SSH keys, or config changes. | 9.8 | 100% | KEV ransomware PoC ×2 |
| massHundreds of thousands of internet-exposed Fortinet admin interfaces (~300k+ exposed FortiGate/FortiProxy management interfaces observed in public scans around… |
Full article413 words · extracted from recordedfuture.com · click to collapse
On June 9th, Fortinet began distributing patches for a new critical vulnerability affecting Fortigate SSL VPN firewalls running on FortiOS or FortiProxy. While Fortinet has not yet released detailed information about the nature of the vulnerability, they have assigned a CVSSv3 score of 9.2 and classified it as an unauthenticated remote code execution (RCE) vulnerability based on a heap buffer overflow. Notably, even dual-factor authentication does not help in mitigating this vulnerability.
Impact and affected versions
Over 200,000 Fortigate firewall instances are reachable from the internet, most likely vulnerable. Although there have been reports indicating that this CVE might have been exploited in a limited number of cases, the likelihood of further exploitation remains high.
According to the official Fortinet advisory, the following are the affected versions of FortiOS and FortiProxy:
According to the official Fortinet analysis of this vulnerability, the recommended actions are:
- Upgrade to the latest version
- If you can’t upgrade, disable your SSL-VPN appliances
- Check your systems for signs of exploitation of previous vulnerabilities, such as FG-IR-22-377 / CVE-2022-40684
- Follow the hardening guidelines provided in the FortiOS 7.2.0 Hardening Guide
- Disabling unused features and managing devices through an out-of-band method whenever feasible reduces the potential for attacks
The Attack Surface Intelligence approach
As soon as we received notification of this new vulnerability, our Attack Surface Quick Reaction Team initiated efforts to locate as many FortiOS and FortiProxy appliances as possible. We utilized various identifiers, including the fingerprinting of the server field and favicons, to identify these appliances. While we could only sometimes determine the precise version of the assets, we erred on the side of caution and chose to inform every customer rather than risk leaving anyone uninformed.
On June 12, all Attack Surface Intelligence customers potentially owning a Fortinet SSL VPN appliance were promptly notified via email, ensuring timely assistance and support within a few hours of the vulnerability's release to provide necessary information and guidance to address the situation effectively. Additionally, Recorded Future Vulnerability Intelligence users are provided additional resources and insights for remediation.
Summary
This blog post highlights a critical vulnerability in Fortigate SSL VPN firewalls, which is currently undergoing patching. Although limited information is available, this unauthenticated remote code execution (RCE) vulnerability poses a significant risk to over 200,000 exposed firewalls. As in previous instances, Attack Surface Intelligence again took the lead in identifying potentially affected software and notifying impacted customers through email, enabling them to address the vulnerability and safeguard their digital assets swiftly.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/fortinet-cve-2023-27997-impact-mitigation-techniques