ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34990
Unauthenticated Path Traversal to Code Execution in Fortinet FortiWLM

CVE-2023-34990 is a relative path traversal (CWE-23) in Fortinet's Wireless LAN Manager (FortiWLM) that allows attackers to execute unauthorized code or commands. It is triggered by specially crafted web requests sent to the management interface, and the CVSS vector (network, low complexity, no privileges, no user interaction) indicates unauthenticated remote exploitation. Successful exploitation yields full command execution on the appliance, and related reporting suggests it can lead to administrator-level access on affected systems. Any organization running FortiWLM 8.6.0 through 8.6.5 or 8.5.0 through 8.5.4 is affected. There is no known public proof-of-concept and the flaw is not yet in CISA's KEV, but the 24.9% EPSS score (98th percentile) indicates a high predicted likelihood of exploitation attempts within 30 days.

Do: Upgrade FortiWLM to a release outside the affected ranges — i.e., later than 8.6.5 on the 8.6 branch or later than 8.5.4 on the 8.5 branch — per Fortinet's advisory. Until patched, restrict access to the FortiWLM web management interface to trusted networks or VPN users and do not expose it directly to the internet. Check device logs for unexpected or anomalous web requests targeting the manager, and prioritize patching internet-facing instances given the high EPSS score.

9.825%
  • Fortinet FortiWLM 8.6.0 through 8.6.5
  • Fortinet FortiWLM 8.5.0 through 8.5.4
moderateplausibly 1,000-10,000 FortiWLM deployments worldwide, with likely hundreds to low thousands of management interfaces internet-exposed
CVE-2023-48782
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters

NVD description · AI analysis pending
8.83%
  • fortinet fortiwlm
CVE-2024-48889
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiManager Cloud version 7.4.4 and below, version 7.2.7 to 7.2.1, version 7.0.12 to 7.0.1 may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests.

NVD description · AI analysis pending
7.22%
  • fortinet fortimanager
  • fortinet fortimanager cloud
Full article582 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 19, 2024Vulnerability / Network Security

Fortinet has issued an advisory for a now-patched critical security flaw impacting Wireless LAN Manager (FortiWLM) that could lead to disclosure of sensitive information.

The vulnerability, tracked as CVE-2023-34990, carries a CVSS score of 9.6 out of a maximum of 10.0. It was originally fixed by Fortinet back on August 18, 2023, but without a CVE designation. The list of supported FortiOS versions was updated in early September.

"A relative path traversal [CWE-23] in FortiWLM may allow a remote unauthenticated attacker to read sensitive files," the company said in an alert released Wednesday.

However, according to a description of the security flaw in the NIST's National Vulnerability Database (NVD), the path traversal vulnerability could also be exploited by an attacker to "execute unauthorized code or commands via specially crafted web requests."

The flaw impacts the following versions of the product -

  • FortiWLM versions 8.6.0 through 8.6.5 (Fixed in 8.6.6 or above)
  • FortiWLM versions 8.5.0 through 8.5.4 (Fixed in 8.5.5 or above)

The company credited Horizon3.ai security researcher Zach Hanley for discovering and reporting the shortcoming. It's worth mentioning here that CVE-2023-34990 refers to the "unauthenticated limited file read vulnerability" the cybersecurity company revealed back in March as part of a broader set of six flaws in FortiWLM.

"This vulnerability allows remote, unauthenticated attackers to access and abuse builtin functionality meant to read specific log files on the system via a crafted request to the /ems/cgi-bin/ezrf_lighttpd.cgi endpoint," Hanley said at the time.

"This issue results from the lack of input validation on request parameters allowing an attacker to traverse directories and read any log file on the system."

A successful exploitation of CVE-2023-34990 could allow the threat actor to read FortiWLM log files and get hold of the session ID of a user and login, thereby allowing them to exploit authenticated endpoints as well.

To make matters worse, the attackers could take advantage of the fact that the web session IDs are static between user sessions to hijack them and gain administrative permissions to the appliance.

That's not all. An attacker could also combine CVE-2023-34990 with CVE-2023-48782 (CVSS score: 8.8), an authenticated command injection flaw that has also been fixed in FortiWLM 8.6.6, to obtain remote code execution in the context of root.

Separately patched by Fortinet is a high-severity operating system command injection vulnerability in FortiManager that may allow an authenticated remote attacker to execute unauthorized code via FGFM-crafted requests.

The vulnerability (CVE-2024-48889, CVSS score: 7.2) has been addressed in the below versions -

  • FortiManager 7.6.0 (Fixed in 7.6.1 or above)
  • FortiManager versions 7.4.0 through 7.4.4 (Fixed in 7.4.5 or above)
  • FortiManager Cloud versions 7.4.1 through 7.4.4 (Fixed in 7.4.5 or above)
  • FortiManager versions 7.2.3 through 7.2.7 (Fixed in 7.2.8 or above)
  • FortiManager Cloud versions 7.2.1 through 7.2.7 (Fixed in 7.2.8 or above)
  • FortiManager versions 7.0.5 through 7.0.12 (Fixed in 7.0.13 or above)
  • FortiManager Cloud versions 7.0.1 through 7.0.12 (Fixed in 7.0.13 or above)
  • FortiManager versions 6.4.10 through 6.4.14 (Fixed in 6.4.15 or above)

Fortinet also noted that a number of older models, 1000E, 1000F, 2000E, 3000E, 3000F, 3000G, 3500E, 3500F, 3500G, 3700F, 3700G, and 3900E, are affected by CVE-2024-48889 provided the "fmg-status" is enabled.

With Fortinet devices becoming an attack magnet for threat actors, it's essential that users keep their instances up-to-date to safeguard against potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/12/fortinet-warns-of-critical-fortiwlm.html