HomeSecurityFortinet patches critical vulnerabilities in SSL VPN and Firewall

Fortinet patches critical vulnerabilities in SSL VPN and Firewall

Fortinet recently patched several critical vulnerabilities affectingFortiProxy SSL VPN and FortiWeb Web Application Firewall (WAF).

Fortinet vulnerabilities
Fortinet patches critical vulnerabilities in SSL VPN and Firewall

The vulnerabilities allowed remote code execution, SQL Injection, and Denial of Service attacks. Some of them were disclosed at least two years ago.

Some of the vulnerabilities listed in the table below have been previously reported in other Fortinet products , but have only recently been fixed in some versions of FortiProxy SSL VPN:

CVE IDVulnerability typeImpacted productsFixed versionsDate first publishedDate Fixed
CVE-2018-13383DoS, RCEFortiProxy SSL VPN 2.0.0 and below, 1.2.8 and below, 1.1.6 and below, 1.0.7 and below.FortiProxy SSL VPN >= 2.0.1 and >= 1.2.9.April 2, 2019February 1, 2021
CVE-2018-13381DoSFortiProxy SSL VPN 2.0.0 and below, 1.2.8 and below, 1.1.6 and below, 1.0.7 and below.FortiProxy SSL VPN >= 2.0.1 and >= 1.2.9.May 17, 2019February 1, 2021
CVE-2020-29015SQL InjectionFortiWeb 6.3.7 and below, 6.2.3 and below.FortiWeb >= 6.3.8, >= 6.2.4Jan 4, 2021Jan 4, 2021
CVE-2020-29016RCEFortiWeb 6.3.5 and below, 6.2.3 and belowFortiWeb >= 6.3.6, >= 6.2.4Jan 4, 2021Jan 4, 2021
CVE-2020-29017RCEFortiDeceptor 3.1.0 and below, 3.0.1 and below.FortiDeceptor >= >= 3.2.0, 3.1.1, >= 3.0.2Jan 4, 2021Jan 4, 2021
CVE-2020-29018RCEFortiWeb 6.3.5 and belowFortiWeb >= 6.3.6Jan 4, 2021Jan 4, 2021
CVE-2020-29019DoSFortiWeb 6.3.7 and below, 6.2.3 and belowFortiWeb >= 6.3.8, >= 6.2.4Jan 4, 2021Jan 4, 2021

The CVE-2018-13381 in FortiProxy SSL VPN can be triggered by a remote, unauthorized user via a crafted POST request.

Due to a buffer overflow in the SSL VPN portal, a specially crafted large POST request can cause a crash when downloaded from the product, leading to a Denial of Service attack.

Another interesting vulnerability in Fortinet's product is CVE-2018-1338. An attacker could use it to cause a VPN overflow via JavaScript's HREF content property.

Through the vulnerabilities, the attacker could remotely execute code, but also carry out a Denial of Service attack.

The vulnerabilities in FortiWeb Web Application Firewall were discovered and reported by researcher Andrey Medov of Positive Technologies.

“The most dangerous of these four vulnerabilities are SQL Injection (CVE-2020-29015) and Buffer Overflow (CVE-2020-29016), as their exploitation does not require authorization.“.

“The first allows obtaining a hash of the system administrator account, due to excessive DBMS user privileges, giving access to the API without decrypting the hash value.“.

“The second vulnerability allows code execution. And the CVE-2020-29018 can allow code execution, but its exploitation requires authorization,” Medov says in a blog post.

Meh Chang and Orange Tsai of DEVCORE Security Research Team have reported the FortiProxy SSL VPN vulnerabilities , while the FortiDeceptor RCE FortiDeceptor RCE was reported to Fortinet by Chua Wei Kiat .

Fortinet patches critical vulnerabilities in SSL VPN and Firewall
Fortinet patches critical vulnerabilities in SSL VPN and Firewall

Critical vulnerabilities in Fortinet products rated as “moderate”

Many of these vulnerabilities have been rated by NVD as “critical,” based on their CVSS 3.1 rating.

However, reports published by Fortinet's FortiGuard Labs describe them as "moderate severity".

For example, the SQL injection vulnerability in FortiWeb can be exploited by an unauthorized user to execute SQL queries or commands via web requests with malicious SQL statements.

This is likely why NVD rated it critical, with a score of 9.8 on the CVSS 3.1 scale. On the other hand, Fortinet rated it “moderate severity” with a score of 6.4.

Fortinet patches critical vulnerabilities in SSL VPN and Firewall
Fortinet patches critical vulnerabilities in SSL VPN and Firewall

In the past, other significant vulnerabilities have been reported in Fortinet products, which are used by financial institutions, governments, companies , etc.

Therefore, all customers of the company must regularly upgrade products to protect themselves from such critical bugs.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS