ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Fortinet Addresses Critical FortiGate SSL

criticalExploit / PoCimportance 60CVE-2023-27997

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27997
Pre-Auth Heap Buffer Overflow RCE in Fortinet FortiOS/FortiProxy SSL-VPN

CVE-2023-27997 is a heap-based buffer overflow (CWE-122, with associated out-of-bounds write CWE-787) in the SSL-VPN component of Fortinet FortiOS and FortiProxy, reachable by unauthenticated users. A remote attacker can trigger it with specially crafted requests to the SSL-VPN web interface, gaining the ability to execute arbitrary code or commands on the gateway. Full control of an edge VPN/firewall appliance enables credential theft, session hijacking, and pivoting into the protected network, which makes the bug attractive to ransomware operators. Any organization exposing the SSL-VPN portal on the affected FortiOS builds (7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below) or FortiProxy builds (7.2.3 and below, 7.0.9 and below, 2.0.12 and below, and 1.1/1.2 all versions) is potentially exposed. The flaw is under active exploitation: CISA added it to the KEV on 2023-06-13 with known ransomware use, EPSS estimates an ~86% probability of exploitation within 30 days (100th percentile), and reporting indicates it was likely being exploited in the wild, with Fortinet also warning that some attackers retained access to FortiGate devices even after patching.

Do: Apply Fortinet's updates to all SSL-VPN-enabled FortiOS and FortiProxy appliances as required by the CISA KEV listing, upgrading each affected branch beyond the listed versions (end-of-life FortiProxy 1.1/1.2 requires migration to a supported release); if SSL-VPN is not needed, disable the web portal or restrict it to trusted source addresses. After patching, hunt for signs of compromise and rotate credentials and VPN-related secrets, since Fortinet warned that some attackers retained access to FortiGate devices post-patching.

9.886% KEV ransomware
  • Fortinet FortiOS (SSL-VPN) 7.2.4 and below; 7.0.11 and below; 6.4.12 and below; 6.0.16 and below
  • Fortinet FortiProxy (SSL-VPN) 7.2.3 and below; 7.0.9 and below; 2.0.12 and below; 1.2 (all versions); 1.1 (all versions)
masson the order of several hundred thousand internet-exposed SSL-VPN endpoints (≈300k–500k per public scans)
Full article319 words · extracted from infosecurity-magazine.com · click to collapse

Network security solution provider Fortinet has patched a critical bug in its FortiOS and FortiProxy SSL-VPN software that could be exploited to hijack equipment.

The vulnerability, identified as CVE-2023-27997 with a CVSS score of 9.2, reportedly allowed remote code execution and was first discovered by a security analyst at Lexfo.

The security fixes were included in the FortiOS firmware versions 6.0.17, 6.2.15, 6.4.13, 7.0.12 and 7.2.5.

Read more on Fortinet vulnerabilities: Organizations Urged to Address Critical Vulnerabilities Found in First Half of 2023

Interestingly, the release notes did not initially mention the critical SSL-VPN RCE vulnerability being addressed. However, security professionals and administrators, including Charles Fol from Lexfo, have hinted that these updates silently addressed the flaw, which was scheduled to be disclosed on June 13 2023.

Writing on Twitter on Monday, Fol revealed that the latest FortiOS updates contain a fix for a critical RCE vulnerability he and Rioru had discovered.

“Fortinet has had to respond to a number of recent vulnerabilities, and this is another good example,” commented Mike Parkin, senior technical engineer at Vulcan Cyber.

According to the security expert, it is not uncommon for a patch to be released to address a vulnerability before publicly acknowledging its existence. 

Currently, it remains uncertain whether the vulnerability has been exploited in real-world attacks or if knowledge of it extends beyond the initial research findings.

“While researchers were able to create a proof of concept, that doesn’t always translate into a weaponized exploit,” Parkin added.

“That said, once the PoC [Proof of Concept] is made public [...] threat actors will try and create their own attack to leverage the exploit, which means Fortinet’s users need to patch their systems as soon as the patches are available.”

A separate PoC was released by Vulcan Cyber last week regarding a new technique to use ChatGPT as an attack vector.

Editorial image credit: T. Schneider / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/fortinet-addresses-fortigate-ssl/