HomeSecurityFortinet: Fix FortiOS SSL-VPN vulnerability

Fortinet: Fix FortiOS SSL-VPN vulnerability

Fortinet informs all customers that they must urgently fix their devices against the dangerous FortiOS SSL-VPN vulnerability, which can be exploited remotely and without authentication control, thus allowing the execution of arbitrary code.

FortiOS SSL-VPN Fortinet

CVE-2022-42475 is a security vulnerability discovered in FortiOS SSL-VPN that allows unauthorized external users to remotely compromise devices and execute malicious code. This buffer overflow flaw can have dire consequences if exploited .

Σήμερα, η Fortinet εξέδωσε μια προειδοποιητική συμβουλή που ενημερώνει για μια ευπάθεια heap-based buffer overflow [CWE-122] που υπάρχει στο FortiOS SSL-VPN και μπορεί να επιτρέψει σε απομακρυσμένα μη εξουσιοδοτημένα άτομα να εκτελέσουν αυθαίρετες εντολές ή κώδικα με ένα μόνο κακόβουλο αίτημα.

As reported by LeMagIT, French cybersecurity firm Olympe Cyberdefense first disclosed the Fortinet zero-day vulnerability , warning users to monitor their logs for suspicious activity until a patch is released

On November 28, Fortinet fixed the bug in FortiOS 7.2.3 (other versions that were released earlier) without publishing any information about its exploit as a zero‑day.

On December 7, BleepingComputer discovered that the company released a confidential TLP:Amber advisory to its customers with additional details about the bug.

Today, Fortinet released the security advisory FG-IR-22-398, publicly warning that the vulnerability has been used in attacks and that all users should update the following releases to fix the flaw.

FortiOS SSL-VPN

Widely used in malicious attacks

Although Fortinet has not yet disclosed details about the vulnerability being exploited, it has published IOCs related to the attacks.

According to Fortinet, if a device is compromised, it will create the following entries in the logs:

Fortinet: Fix FortiOS SSL-VPN vulnerability

Fortinet also shared a list of IP addresses observed to be exploiting the vulnerability, which is listed below.

Fortinet: Fix FortiOS SSL-VPN vulnerability

According to Grey Noise, a threat intelligence company, the address 103.131.189.143 was observed in October performing network scans!

If you cannot repair your system immediately, Olympe Cyberdefense advises customers to thoroughly inspect the logs, disable the VPN-SSL function, and create access rules to limit connections from specific IP addresses.

For those who do not know what Fortinet does

Fortinet provides a suite of security solutions that help organizations protect their networks from threats. This cybersecurity platform integrates multiple technologies into a single system, enabling organizations to secure their endpoints, networks, applications and data to prevent malicious attacks. In addition, Fortinet offers advanced threat intelligence and analytics capabilities that provide customers with deeper insights into their networks and real-time visibility into potential threats.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS