ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

Critical FortiClient EMS vulnerability fixed, (fake?) PoC for sale (CVE-2023-48788)

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-48788

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-48788
Unauthenticated SQL Injection in Fortinet FortiClient EMS

Fortinet FortiClient EMS — the central management server for FortiClient endpoint deployments — contains a SQL injection flaw (CWE-89) in versions 7.0.1 through 7.0.10 and 7.2.0 through 7.2.2. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) shows it can be triggered remotely with no credentials and no user interaction: an unauthenticated attacker sends specially crafted packets to the vulnerable management server and can execute unauthorized code or commands. Successful exploitation effectively yields remote code execution on the EMS server and access to its database, enabling follow-on actions such as credential theft, abuse of endpoint management functions, and ransomware deployment. Any organization running the affected EMS versions is exposed, especially where the management server is reachable from the internet. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-03-25 with known ransomware use, and EPSS assigns a ~98.4% probability of exploitation within 30 days (100th percentile).

Do: Upgrade FortiClient EMS to the fixed releases per Fortinet's advisory for this CVE (7.2.3 and 7.0.11 or later, i.e., beyond the 7.2.2 and 7.0.10 affected ranges); the CISA KEV required action is to apply vendor mitigations or discontinue use if mitigations are unavailable. Until patched, limit exposure of the EMS web interface to untrusted networks and hunt for signs of compromise — anomalous requests to the management console, unexpected database or admin activity, and follow-on ransomware behavior — since exploitation with known ransomware use is confirmed.

9.898% KEV ransomware
  • fortinet FortiClient Enterprise Management Server (EMS) 7.2.0 through 7.2.2 and 7.0.1 through 7.0.10
largetens of thousands of EMS deployments worldwide, with a smaller subset (likely thousands) internet-exposed
Full article516 words · extracted from helpnetsecurity.com · click to collapse

A recently fixed SQL injection vulnerability (CVE-2023-48788) in Fortinet’s FortiClient Endpoint Management Server (EMS) solution has apparently piqued the interest of many: Horizon3’s Attack Team means to publish technical details and a proof-of-concept exploit for it next week, and someone is attempting to sell a PoC for less than $300 via GitHub.

About CVE-2023-48788

CVE-2023-48788 is one of the several vulnerabilities recently patched by Fortinet.

“An improper neutralization of special elements used in an SQL Command (‘SQL Injection’) vulnerability [CWE-89] in FortiClientEMS may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted requests,” the company’s product security incident response team pithily states in the associated advisory.

The team also shared that the vulnerability was “co-discovered and reported by Thiago Santana from Fortinet ForticlientEMS development team and UK NCSC”, but did not say whether it has been or is currently being exploited in attacks in the wild.

A PoC for CVE-2023-48788

As of Wednesday, someone has set up a GitHub page advertising a “new exploit” for CVE-2023-48788, and linked to a post on SatoshiDisk.com, a web-based platform where users can upload files they want to sell and other users can download them if they pay the set price.

PoC exploit for CVE-2023-48788 offered for sale

Here’s the thing, though: there’s no way to check if the PoC is real or fake before buying it. And we know that scammers and malware peddlers have been using this same pretext in the past to steal money and to deliver malware.

“I think the probability is low that the exploit sold by [this seller] is real. Currently, I do not see an exploit advertised anywhere else,” Dr. Johannes Ullrich, the founder of the SANS Internet Storm Center (ISC), told Help Net Security.

“On the other hand, if this is a relatively simple SQL injection issue, exploitation may not be that difficult, which could also explain the low price.”

He also noted that the vulnerability does not affect Fortinet gateway devices, but FortiClient EMS, instances of which are less likely to be reachable via the internet. According to sites like Shodan, there are only about a couple hundred systems currently exposed, he pointed out.

“At this point, I see almost no scans for Fortinet in [ISC’s] honeypots, and no actual exploit attempt, another indicator that there is no actual exploit widely available right now,” he concluded.

UPDATE (March 21, 2024, 10:50 a.m. ET):

Horizon3.ai has published a deep-dive into the vulnerability and a partial PoC exploit that triggers the SQL injection flaw but doesn’t enable remote code execution.

According to Greynoise’s tag for CVE-2023-48788, exploitation attempts are yet to be spotted, but the company has updated the security advisory, which now says that “this vulnerability is exploited in the wild.”

UPDATE (April 15, 2024, 04:20 a.m. ET):

Red Canary threat researchers have spotted CVE-2023-48788 being exploited by attackers.

“The exploit activity we observed followed a pattern that started with inbound external network connections to the FCMdaemon process and ended with attempts to download and execute RMM tools or PowerShell-based backdoors,” they said last week.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/