ZeroHour
The Recordpublished ()ingested

Nearly 70% of FortiGate Firewalls are vulnerable to new bug, experts say

criticalRansomwareimportance 60CVE-2023-27997

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27997
Pre-Auth Heap Buffer Overflow RCE in Fortinet FortiOS/FortiProxy SSL-VPN

CVE-2023-27997 is a heap-based buffer overflow (CWE-122, with associated out-of-bounds write CWE-787) in the SSL-VPN component of Fortinet FortiOS and FortiProxy, reachable by unauthenticated users. A remote attacker can trigger it with specially crafted requests to the SSL-VPN web interface, gaining the ability to execute arbitrary code or commands on the gateway. Full control of an edge VPN/firewall appliance enables credential theft, session hijacking, and pivoting into the protected network, which makes the bug attractive to ransomware operators. Any organization exposing the SSL-VPN portal on the affected FortiOS builds (7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below) or FortiProxy builds (7.2.3 and below, 7.0.9 and below, 2.0.12 and below, and 1.1/1.2 all versions) is potentially exposed. The flaw is under active exploitation: CISA added it to the KEV on 2023-06-13 with known ransomware use, EPSS estimates an ~86% probability of exploitation within 30 days (100th percentile), and reporting indicates it was likely being exploited in the wild, with Fortinet also warning that some attackers retained access to FortiGate devices even after patching.

Do: Apply Fortinet's updates to all SSL-VPN-enabled FortiOS and FortiProxy appliances as required by the CISA KEV listing, upgrading each affected branch beyond the listed versions (end-of-life FortiProxy 1.1/1.2 requires migration to a supported release); if SSL-VPN is not needed, disable the web portal or restrict it to trusted source addresses. After patching, hunt for signs of compromise and rotate credentials and VPN-related secrets, since Fortinet warned that some attackers retained access to FortiGate devices post-patching.

9.886% KEV ransomware
  • Fortinet FortiOS (SSL-VPN) 7.2.4 and below; 7.0.11 and below; 6.4.12 and below; 6.0.16 and below
  • Fortinet FortiProxy (SSL-VPN) 7.2.3 and below; 7.0.9 and below; 2.0.12 and below; 1.2 (all versions); 1.1 (all versions)
masson the order of several hundred thousand internet-exposed SSL-VPN endpoints (≈300k–500k per public scans)
Full article580 words · extracted from therecord.media · click to collapse

Cybersecurity experts are raising the alarm about a new vulnerability that leaves hundreds of thousands of Fortinet customers vulnerable to attack.

Concerns about the issue — tracked as CVE-2023-27997 — grew last month due to how widely used Fortinet’s SSL-VPN product is among government organizations. Fortinet released a patch in June for the bug, which has a “critical” severity score of 9.8 out of 10 and was discovered by Lexfo Security vulnerability researchers.

Fortinet said the issue “may have been exploited in a limited number of cases” and noted that the hacking campaign was “targeted at government, manufacturing, and critical infrastructure.”

But this weekend, concerns were reignited when researchers from security firm Bishop Fox announced that they internally developed an exploit for CVE-2023-27997.

“There are 490,000 affected SSL VPN interfaces exposed on the internet, and roughly 69% of them are currently unpatched. You should patch yours now,” they said in a blog post explaining their findings.

“The exploit runs in approximately one second, which is significantly faster than the demo video on a 64-bit device shown by Lexfo.”

Using the researcher’s calculations, that leaves more than 335,000 instances currently vulnerable to the issue. The experts from Bishop Fox also expressed alarm at the dozens of unpatched instances that are running years-old versions, dozens of which reached end-of-life years ago.

Several cybersecurity experts echoed Bishop Fox’s alarm about the issue, explaining that the need to patch was an urgent problem.

Tanium chief security advisor Timothy Morris said the seriousness of the issue “cannot be understated” considering that exploit code now exists and the devices at the heart of the problem are typically on the perimeter of an organization.

He noted that many organizations have redundant systems that are running as spares, meaning several most likely need to be patched within any one company.

“This is one of those examples where the CVS rating feels like the Richter scale. Remote code execution on a security appliance is about as bad as it can get,” said Andrew Barratt, vice president at cybersecurity firm Coalfire.

“These devices are both the doors to the network, and a large volume of the devices still being vulnerable is probably due to an inability to take these firewalls offline and test the patch with the associated impact on the business.”

Other cybersecurity experts, including Ontinue director of threat intelligence Andre van der Walt, added that in recent years, several high-profile FortiGate vulnerabilities have been discovered and exploited.

There was some concern that Chinese hackers, as part of the Volt Typhoon hacking group, exploited the bug during an attack on the telecommunications network of Guam, a U.S. territory in the Pacific Ocean.

Fortinet dispelled the rumors that CVE-2023-27997 was involved in that compromise but said it “expects all threat actors, including those behind the Volt Typhoon campaign, to continue to exploit unpatched vulnerabilities in widely used software and devices.”

CVE-2023-27997, van der Walt said, could lead to data breaches, ransomware attacks, and other serious consequences.

He noted that the findings from Bishop Fox mirrors the overall trend of patching lagging significantly behind addressing new exposure in the attack surface, regardless of the technology in question.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/fortigate-firewalls-vulnerable-to-new-bug