ZeroHour
The Recordpublished ()ingested

CISA adds Fortinet bug to exploited vulnerabilities list

criticalVulnerability exploited in the wildimportance 60CVE-2022-40684CVE-2018-13379

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-13379
Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN

CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors.

Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible.

9.8100% KEV ransomware
  • Fortinet FortiOS
mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices)
CVE-2022-40684
Admin-Interface Auth Bypass in Fortinet FortiOS, FortiProxy & FortiSwitchManager

Fortinet's FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability (CWE-288) that lets an unauthenticated remote attacker gain access to the administrative interface. It is triggered by sending specially crafted HTTP or HTTPS requests directly to the admin interface, with no credentials or exploit code required. By bypassing authentication, an attacker can perform administrative operations on the device, such as modifying configuration or creating privileged accounts. Any organization running the affected products is exposed, particularly where the management interface is reachable from the internet. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 with known ransomware use, and EPSS assigns it roughly a 100% probability of exploitation within 30 days, although no public PoC is known.

Do: Upgrade FortiOS, FortiProxy, and FortiSwitchManager to the fixed releases identified in Fortinet's advisory per the KEV required action. As mitigation, restrict access to the admin interface (e.g., disable WAN-facing management and use local-in policies or allow-lists for management IPs). Review admin logs and device configuration for signs of unauthorized access, such as unexpected admin accounts, added SSH keys, or config changes.

9.8100% KEV ransomware PoC ×2
  • Fortinet FortiOS
  • Fortinet FortiProxy
  • Fortinet FortiSwitchManager
massHundreds of thousands of internet-exposed Fortinet admin interfaces (~300k+ exposed FortiGate/FortiProxy management interfaces observed in public scans around…
Full article659 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) added a recently discovered vulnerability in Fortinet appliances to its catalog of known exploited issues on Tuesday.

CISA said federal civilian agencies have until November 1 to address CVE-2022-40684 — a vulnerability affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager.

On Monday, Fortinet confirmed reports that the vulnerability was being exploited and urged its customers to upgrade their systems as soon as possible.

Both Fortinet and CISA said the vulnerability allows unauthenticated attackers to “perform operations on the administrative interface.” 

BleepingComputer and several security researchers, including Tenable senior research engineer Claire Tills, said Fortinet began sending out warnings about the issue to certain customers on Friday after releasing a patch Thursday.

Fortinet told customers that the vulnerability is “critical” and "should be dealt with the utmost urgency.”

#Fortinet is currently advising it's customers on a high severity #vulnerability in
FortiOS: From 7.0.0 to 7.0.6 and from 7.2.0 to 7.2.1
FortiProxy: From 7.0.0 to 7.0.6 and 7.2.0#CVE: CVE-2022-40684#authbypass #RCE #prepareforimpact@campuscodi @uuallan @GossiTheDog pic.twitter.com/eiVrtsozC0— Gi7w0rm (@Gi7w0rm) October 7, 2022

Tills said the private alerts from Fortinet were designed to potentially give customers a headstart in patching before going public with more information that could be used by malicious actors.

“There was significant speculation surrounding the flaw in the vacuum of official, public details from Fortinet,” Tills said.

Security researchers with Horizon3.ai have already reversed the vulnerability and plan to publish a proof-of-concept later this week.

Zach Hanley, chief attack engineer at Horizon3.ai, told The Record that it's hard to get a good idea of how common the appliances are used but said there are at least 10,000 vulnerable tools exposed to the internet. 

"Fortinet devices are some of the most popular appliances used by organizations worldwide, and based on the Shodan results the United States is particularly at risk if their devices remain unpatched,” he said. 

“Fortinet has observed in-the-wild exploitation of the issue already in at least one case, and reports this week point to other threat actors starting to abuse it. Vulnerabilities affecting devices on the edge of corporate networks are among the most sought after by threat actors because it leads to breaching the perimeter, and CVE-2022-40684 allows exactly this.”

Another appliance vuln down...

CVE-2022-40684, affecting multiple #Fortinet solutions, is an auth bypass that allows remote attackers to interact with all management API endpoints.

Blog post and POC coming later this week. Patch now. pic.twitter.com/YS7svIljAw— Horizon3 Attack Team (@Horizon3Attack) October 10, 2022

He noted that past Fortinet vulnerabilities like CVE-2018-13379 have remained some of the top exploited vulnerabilities over the years and “this one will likely be no different." CVE-2018-13379 has been exploited by a wide range of threat actors including ransomware groups and state-backed hackers.

Hanley added that they do not have information on how widely exploited it is other than the case reported by Fortinet. According to Hanley, several MSSP providers have indicated that they think some of their customers may be compromised.

Tills and Vulcan Cyber’s Mike Parkin explained that vulnerabilities in security products can always be problematic, especially when it’s on an edge or gateway device. 

In addition to updating the appliances or implementing workarounds that can help mitigate risk, customers should at the very least restrict access to the devices per industry best practices, Parkin said.

“Now that Fortinet has confirmed this flaw has been exploited, and given threat actors’ penchant for targeting older FortiOS vulnerabilities, organizations should urgently apply the patches,” Tills said. 

“As more details about the vulnerability come to light, the higher the likelihood that threat actors will adopt the flaw into their attacks.”

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-fortinet-bug-to-exploited-vulnerabilities-list