HomeSecurityFortinet: Fixes Critical RCE Bug in Fortigate SSL VPN

Fortinet: Fixes Critical RCE Bug in Fortigate SSL VPN

Fortinet SSL VPN

Fortinet has released new updates to its Fortigate firmware to address a critical security vulnerability that allows remote code execution (RCE) and affects devices SSL VPN . As the company states, “ a secure sockets layer VPN (SSL VPN) allows individual users to access network , client-server applications, and internal network utilities and directories without the need for specialized software. SSL VPNs provide secure communication over an encrypted connection for all types of devices, regardless of whether the accessed over the public internet or another secure network an organization’s network is .”

The updates were released on Friday to FortiOS firmware versions 6.0.17, 6.2.15, 6.4.13, 7.0.12 and 7.2.5.

It appears that the updates have “silently” fixed the critical SSL VPN RCE vulnerability that will be disclosed tomorrow, Tuesday, June 13.

See also: Advanced spyware malware 'Stealth Soldier' ​​hits Libyan companies

“The vulnerability would allow an attacker to intervene via the VPN, even if MFA is enabled,” says French cybersecurity firm Olympe Cyberdefense.

Fortinet typically releases security before a critical vulnerability is disclosed, giving customers enough time to update their devices before cybercriminals can exploit the updates to attack those who haven’t immediately protected their systems. Threat actors can compare newer versions of the operating system with older ones to find out what the update does and, based on that information, develop an exploit.

Lexfo Security researcher Charles Folhas made additional revelations about the vulnerability in Fortinet's SSL VPN. As he told BleepingComputer, the new FortiOS updates include a fix for a critical RCE vulnerability discovered by him and Rioru.

“Fortinet has released a patch for CVE-2023-27997, the vulnerability that @DDXhunter and I reported,” reads a tweet from Fol.

See also: Dozens of popular Minecraft mods have been infected with malware

The researcher urged users to apply the update immediately and said that more details would be announced later.

Fol confirmed to BleepingComputer that this should be considered an urgent patch for Fortinet administrators, as the vulnerability is likely to be analyzed and discovered quickly by threat.

Fortigate

Fortinet devices are among the most popular firewall and VPN devices on the market. For this reason, they are also a favorite target for hackers.

A search on Shodanshows that over 250,000 Fortigate firewalls are accessible from the Internet, and as this bug affects all previous versions, the majority are at risk.

In the past, cybercriminals have exploited vulnerabilities in SSL-VPN devices within days of the release of patches. Attackers typically use them to gain initial access to networks to steal data and carry out ransomware.

Therefore, administrators should apply Fortinet security updates as soon as they become available.

See also: PoC released for Windows Win32k bug used in attacks

BleepingComputer reached out to Fortinet for more information. Shortly after, they received the following response:

“Timely and ongoing communication with our customers is a key component in our efforts to better protect and secure organizations . There are instances where advance, confidential customer communications may include early warning to allow customers to further enhance their security posture before an advisory is publicly released to the general public. This process follows best practices for responsible disclosure to ensure our customers have the information they need to make informed risk-. For more information about Fortinet’s responsible disclosure process, please visit: https://www.fortiguard.com/psirt_policy“.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS