Fortinet recently patched several critical vulnerabilities affectingFortiProxy SSL VPN and FortiWeb Web Application Firewall (WAF).

The vulnerabilities allowed remote code execution, SQL Injection, and Denial of Service attacks. Some of them were disclosed at least two years ago.
Some of the vulnerabilities listed in the table below have been previously reported in other Fortinet products , but have only recently been fixed in some versions of FortiProxy SSL VPN:
| CVE ID | Vulnerability type | Impacted products | Fixed versions | Date first published | Date Fixed |
| CVE-2018-13383 | DoS, RCE | FortiProxy SSL VPN 2.0.0 and below, 1.2.8 and below, 1.1.6 and below, 1.0.7 and below. | FortiProxy SSL VPN >= 2.0.1 and >= 1.2.9. | April 2, 2019 | February 1, 2021 |
| CVE-2018-13381 | DoS | FortiProxy SSL VPN 2.0.0 and below, 1.2.8 and below, 1.1.6 and below, 1.0.7 and below. | FortiProxy SSL VPN >= 2.0.1 and >= 1.2.9. | May 17, 2019 | February 1, 2021 |
| CVE-2020-29015 | SQL Injection | FortiWeb 6.3.7 and below, 6.2.3 and below. | FortiWeb >= 6.3.8, >= 6.2.4 | Jan 4, 2021 | Jan 4, 2021 |
| CVE-2020-29016 | RCE | FortiWeb 6.3.5 and below, 6.2.3 and below | FortiWeb >= 6.3.6, >= 6.2.4 | Jan 4, 2021 | Jan 4, 2021 |
| CVE-2020-29017 | RCE | FortiDeceptor 3.1.0 and below, 3.0.1 and below. | FortiDeceptor >= >= 3.2.0, 3.1.1, >= 3.0.2 | Jan 4, 2021 | Jan 4, 2021 |
| CVE-2020-29018 | RCE | FortiWeb 6.3.5 and below | FortiWeb >= 6.3.6 | Jan 4, 2021 | Jan 4, 2021 |
| CVE-2020-29019 | DoS | FortiWeb 6.3.7 and below, 6.2.3 and below | FortiWeb >= 6.3.8, >= 6.2.4 | Jan 4, 2021 | Jan 4, 2021 |
The CVE-2018-13381 in FortiProxy SSL VPN can be triggered by a remote, unauthorized user via a crafted POST request.
Due to a buffer overflow in the SSL VPN portal, a specially crafted large POST request can cause a crash when downloaded from the product, leading to a Denial of Service attack.
Another interesting vulnerability in Fortinet's product is CVE-2018-1338. An attacker could use it to cause a VPN overflow via JavaScript's HREF content property.
Through the vulnerabilities, the attacker could remotely execute code, but also carry out a Denial of Service attack.
The vulnerabilities in FortiWeb Web Application Firewall were discovered and reported by researcher Andrey Medov of Positive Technologies.
“The most dangerous of these four vulnerabilities are SQL Injection (CVE-2020-29015) and Buffer Overflow (CVE-2020-29016), as their exploitation does not require authorization.“.
“The first allows obtaining a hash of the system administrator account, due to excessive DBMS user privileges, giving access to the API without decrypting the hash value.“.
“The second vulnerability allows code execution. And the CVE-2020-29018 can allow code execution, but its exploitation requires authorization,” Medov says in a blog post.
Meh Chang and Orange Tsai of DEVCORE Security Research Team have reported the FortiProxy SSL VPN vulnerabilities , while the FortiDeceptor RCE FortiDeceptor RCE was reported to Fortinet by Chua Wei Kiat .

Critical vulnerabilities in Fortinet products rated as “moderate”
Many of these vulnerabilities have been rated by NVD as “critical,” based on their CVSS 3.1 rating.
However, reports published by Fortinet's FortiGuard Labs describe them as "moderate severity".
For example, the SQL injection vulnerability in FortiWeb can be exploited by an unauthorized user to execute SQL queries or commands via web requests with malicious SQL statements.
This is likely why NVD rated it critical, with a score of 9.8 on the CVSS 3.1 scale. On the other hand, Fortinet rated it “moderate severity” with a score of 6.4.

In the past, other significant vulnerabilities have been reported in Fortinet products, which are used by financial institutions, governments, companies , etc.
Therefore, all customers of the company must regularly upgrade products to protect themselves from such critical bugs.
Source: Bleeping Computer
