ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Fortinet plugs critical security hole in FortiNAC, with a PoC incoming (CVE-2022-39952)

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-39952CVE-2021-42756CVE-2022-42475

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-42756
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and bel

Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.

NVD description · AI analysis pending
9.835%
  • fortinet fortiweb
CVE-2022-39952
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

NVD description · AI analysis pending
9.8100%
  • fortinet fortinac
CVE-2022-42475
Unauthenticated Heap Overflow in Fortinet FortiOS/FortiProxy SSL-VPN (Critical RCE)

CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow in the SSL-VPN service of Fortinet FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it by sending specifically crafted requests to an exposed SSL-VPN interface, with no user interaction or credentials required. Successful exploitation yields arbitrary code or command execution on the appliance, giving attackers a foothold on the perimeter device from which they can pivot into internal networks. Any organization running the listed FortiOS (6.0 through 7.2) or FortiProxy (7.0/7.2) versions with SSL-VPN enabled is affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, has near-certain exploitation probability (EPSS 99.5%), and has been used in targeted government attacks and a Chinese-nexus espionage campaign that compromised over 20,000 systems, with attackers also noted to retain access even after patching.

Do: Upgrade FortiOS and FortiProxy to fixed releases per Fortinet advisory FG-IR-22-398 (any version beyond the listed affected ranges), and reboot the appliance after patching to clear lingering SSL-VPN sessions since attackers have been observed retaining access post-patch. Check for indicators of compromise such as unknown local accounts, unexpected processes, and anomalous historical logins, and rotate SSL-VPN credentials if compromise is suspected. If SSL-VPN is not required, disable it or restrict exposure to trusted sources until patched.

9.899% KEV ransomware PoC
  • Fortinet FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, and 6.0.15 and earlier
  • Fortinet FortiProxy SSL-VPN 7.2.0 through 7.2.1, and 7.0.7 and earlier
masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL-VPN endpoints (well over 100,000; 20,000+ confirmed victims in a single campaign)

Indicators of compromiseAll →

TypeIndicatorContext
domainhorizon3.aiVE-2022-42475 ). UPDATE (February 21, 2023, 09:25 a.m. ET): Horizon3.ai has released the PoC exploit and indicators of compromise.
Full article403 words · extracted from helpnetsecurity.com · click to collapse

Fortinet has dropped fixes for 40 vulnerabilities in a variety of its products, including two critical vulnerabilities (CVE-2022-39952, CVE-2021-42756) affecting its FortiNAC and FortiWeb solutions.

CVE-2022-39952

Since cyberattackers love to exploit vulnerabilities in Fortinet enterprise solutions and a PoC exploit for CVE-2022-39952 is expected to be released soon, admins are advised to get a move on patching.

About the vulnerabilities

CVE-2022-39952 is an external control of file name or path vulnerability in the webserver of FortiNAC, Fortinet’s network access control solution. It can be exploited by an unauthenticated attacker to perform arbitrary write on a vulnerable system.

It has been fixed in FortiNAC version 9.4.1 or above, 9.2.6 or above, 9.1.8 or above, and 7.2.0 or above.

Horizon3.ai’s Attack Team has already announced they will soon be releasing a PoC and a blog post detailing the exploitation:

CVE-2022-39952, announced today, allows for unauthenticated RCE against #Fortinet FortiNAC as the root user. Blog post and POC to be released soon.

See Fortinet's PSIRT: https://t.co/sBsrs8Wxqb pic.twitter.com/EqkIo3ap4s

— Horizon3 Attack Team (@Horizon3Attack) February 17, 2023

CVE-2021-42756 covers multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb, the company’s web application firewall solution. The vulnerability can be triggered via a specifically crafted HTTP request and may allow an unauthenticated remote attacker to achieve arbitrary code execution.

It has been fixed in FortiWeb version 7.0.0 or above, 6.3.17 or above, 6.2.7 or above, 6.1.3 or above, and 6.0.8 or above.

Both vulnerabilities have been unarthed by members of the Fortinet Product Security team, but the company did not mention why it took so long to push fixes for the latter (the CVE number indicates it has been discovered in 2021).

Most of the remaining fixed vulnerabilities have also been found by Fortinet employees, which points to a concerted internal push to pinpoint and fix security weaknesses in the company’s products.

Other solutions admins should update are:

  • FortiADC (advanced application delivery controller)
  • FortiAnalyzer (log management, analytics, and reporting platform)
  • FortiExtender (WAN connections extender)
  • FortiOS (operating system used in Fortinet hardware, including FortiGate firewalls)
  • FortiProxy (secure web proxy/gateway)
  • FortiAuthenticator (user identity management)
  • The FortiSwitchManager module
  • FortiPortal (portal for service providers)
  • FortiSandbox (malware sandbox)
  • FortiWAN (multi-WAN management)

Most recently, attackers have been spotted exploiting a FortiOS vulnerability (CVE-2022-42475).

UPDATE (February 21, 2023, 09:25 a.m. ET):

Horizon3.ai has released the PoC exploit and indicators of compromise. Greynoise has created a tag to flag exploitation attempts in the wild.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/02/20/cve-2022-39952/