ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Fortinet releases patches for publicly undisclosed critical FortiManager vulnerability

criticalVulnerabilityimportance 60CVE-2024-23113

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-23113
Format String Vulnerability Enables Unauthenticated RCE in Fortinet FortiOS and FortiProxy

CVE-2024-23113 is a use of externally-controlled format string (CWE-134) in multiple Fortinet products, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specially crafted packets to an affected device. The flaw carries a critical CVSS 3.1 score of 9.8 (network vector, no privileges or user interaction required, high impact on confidentiality, integrity, and availability). It affects FortiOS 7.0.0 through 7.0.13, 7.2.0 through 7.2.6, and 7.4.0 through 7.4.2; FortiProxy 7.0.0 through 7.0.14, 7.2.0 through 7.2.8, and 7.4.0 through 7.4.2; FortiPAM 1.0.0 through 1.0.3, 1.1.0 through 1.1.2, and 1.2.0; and FortiSwitchManager 7.0.0 through 7.0.3 and 7.2.0 through 7.2.3. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-10-09 and warns it is likely being exploited in the wild, though no public proof-of-concept is known. Scanning coverage reported in the trade press indicates roughly 87,000 or more internet-exposed Fortinet devices remained vulnerable and open to attack after disclosure.

Do: Upgrade affected FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager deployments to a patched release per Fortinet's advisory, since the data does not specify fixed build numbers. Until patching is complete, restrict management interface access to trusted sources, minimize internet exposure of affected devices, and verify your version falls within the affected ranges above. Treat this as an actively exploited vulnerability per CISA's KEV listing (added 2024-10-09) and prioritize it accordingly.

9.862% KEV
  • Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13
  • Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14
  • Fortinet FortiPAM 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3
  • +1 more
large≈87,000+ internet-exposed Fortinet devices per public scans (FortiOS/FortiProxy deployments; total installed base larger, affected-version share unknown)
Full article429 words · extracted from helpnetsecurity.com · click to collapse

In the last couple of days, Fortinet has released critical security updates for FortiManager, to fix a critical vulnerability that is reportedly being exploited by Chinese threat actors.

Security updates are trickling out

The company, which is known for pushing out fixes for critical vulnerabilities before disclosing their existence to the public, has privately notified select customers a week ago and shared temporary mitigation advice.

The advice apparently includes configuring FortiManager to prevent devices with an unknown serial number (i.e., an unauthorized device) to register/connect to them.

Limiting access to FortiManager installations is also generally a good idea, but implementing the patches once they are released is essential. Some are already available from Fortinet’s support portal.

No CVE, no details (yet)

The company has yet to publicly reveal details about or the CVE associated with this vulnerability, though the suggested mitigation might indicate that the issue resides in the “Fortigate to FortiManager” (fgfm) connection / communication / management capability.

Whether it is related to CVE-2024-23113 – a format string vulnerability that affects the FortiOS fgfm daemon – is open to speculation.

CVE-2024-23113 was patched earlier this year in FortiOS, FortiPAM, FortiProxy and FortiWeb. In early October, CISA confirmed that it is being exploited by attackers, and watchTowr Lab researchers released a deep-dive into it.

UPDATE (October 23, 2024, 03:00 a.m. ET):

Fortinet has still not publicly released a security advisory for this issue or assigned it a CVE. The company’s product security incident response team (PSIRT) web page is intermittently accessible.

Time will tell whether their decision to keep this information close to the chest and engage in limited, private disclosure was correct. In the meantime, discussions on Reddit show that some FortiManager users did not get the memo and have had to resort to searching for crucial information from (unofficial) online sources.

One of these sources is security researcher Kevin Beaumont, who has been following this situation for the last ten days or so.

In his recent post, he said that the vulnerability is being exploited by nation state threat actors in espionage campaigns via managed service providers. Based on things he’s witnessed on his own FortiManager honeypot and information he found online, he has provided his view of where the flaw resides and what it allows.

UPDATE (October 24, 2024, 11:10 a.m. ET):

The title has been modified to specify that the vulnerability was not publicly disclosed by Fortinet at time of writing, but only privately.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/10/21/fortimanager-critical-vulnerability/