Over Two-Thirds of FortiGate Firewalls Still at Risk
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-27997 | Pre-Auth Heap Buffer Overflow RCE in Fortinet FortiOS/FortiProxy SSL-VPN CVE-2023-27997 is a heap-based buffer overflow (CWE-122, with associated out-of-bounds write CWE-787) in the SSL-VPN component of Fortinet FortiOS and FortiProxy, reachable by unauthenticated users. A remote attacker can trigger it with specially crafted requests to the SSL-VPN web interface, gaining the ability to execute arbitrary code or commands on the gateway. Full control of an edge VPN/firewall appliance enables credential theft, session hijacking, and pivoting into the protected network, which makes the bug attractive to ransomware operators. Any organization exposing the SSL-VPN portal on the affected FortiOS builds (7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below) or FortiProxy builds (7.2.3 and below, 7.0.9 and below, 2.0.12 and below, and 1.1/1.2 all versions) is potentially exposed. The flaw is under active exploitation: CISA added it to the KEV on 2023-06-13 with known ransomware use, EPSS estimates an ~86% probability of exploitation within 30 days (100th percentile), and reporting indicates it was likely being exploited in the wild, with Fortinet also warning that some attackers retained access to FortiGate devices even after patching. Do: Apply Fortinet's updates to all SSL-VPN-enabled FortiOS and FortiProxy appliances as required by the CISA KEV listing, upgrading each affected branch beyond the listed versions (end-of-life FortiProxy 1.1/1.2 requires migration to a supported release); if SSL-VPN is not needed, disable the web portal or restrict it to trusted source addresses. After patching, hunt for signs of compromise and rotate credentials and VPN-related secrets, since Fortinet warned that some attackers retained access to FortiGate devices post-patching. | 9.8 | 86% | KEV ransomware |
| masson the order of several hundred thousand internet-exposed SSL-VPN endpoints (≈300k–500k per public scans) |
Full article422 words · extracted from infosecurity-magazine.com · click to collapse
Approximately 69% of FortiGate firewalls affected by a recently discovered FortiOS vulnerability remain unpatched, according to security researchers at Bishop Fox.
The flaw (CVE-2023-27997) could lead to remote code execution (RCE). It was patched by Fortinet in mid-June.
Read more about this vulnerability: Fortinet Addresses Critical FortiGate SSL-VPN Vulnerability
In a recently published advisory, Bishop Fox’s Capability Development team said they have successfully developed an exploit for the vulnerability.
“Our exploit smashes the heap, connects back to an attacker-controlled server, downloads a BusyBox binary, and opens an interactive shell,” explained Caleb Gross, director of Capability Development.
The entire process reportedly takes approximately one second, significantly faster than an earlier demonstration provided by Lexfo.
Gross added that a search on Shodan, a search engine for internet-connected devices, revealed that nearly 490,000 SSL VPN interfaces exposed on the internet are affected by this vulnerability.
“This FortiOS heap overflow vulnerability is rated as critical and requires a firmware update,” commented Timothy Morris, chief security advisor at Tanium.
“That is reason enough to patch; however, the fact that exploit code exists and that these security appliances are typically on the perimeter requires immediate attention.”
It is important to note that previous reports estimating 250,000 exposed FortiGate firewalls based on SSL certificates alone may not accurately reflect the actual number of vulnerable devices, according to Bishop Fox.
This would be because the search query used in those reports did not specifically target SSL VPN interfaces, where this vulnerability resides.
To identify vulnerable devices accurately, Gross said a more effective approach involves searching for servers returning a specific HTTP response header, then further filtering the results based on devices redirecting to a particular path.
An in-depth analysis revealed that only 153,414 devices on the internet had been patched, leaving a concerning 69% of devices unpatched.
The Bishop Fox analysis also highlighted the distribution of different major operating system versions. While a significant number of installations run the latest version, FortiOS 7, there are still devices running older versions, particularly version 5, which has reached its end of life.
“The [...] findings highlight that the risk of appliances and embedded devices carry the same security risks as traditional computing devices but are a bigger pain to upgrade,” commented John Bambenek, principal threat hunter at Netenrich.
“Until manufacturers make it easy, and automatic patching is simply the default, we will continue to see these kinds of patterns.”
Bishop Fox urged all FortiGate firewall users to promptly follow Fortinet’s advisory and patch their devices.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/two-thirds-fortigate-risk/