HomeSecurityFortinet fixes critical FortiNAC remote command execution bug

Fortinet fixes critical FortiNAC remote command execution bug

Cybersecurity solutions company Fortinet has updated its zero-trust access solution FortiNAC to address a critical vulnerability that attackers could exploit to execute code and commands.

See also: The top 5 cybersecurity threats in 2023

Fortinet

FortiNAC enables organizations to manage network-wide access policies, gain visibility into devices and users, and secure the network from unauthorized access and threats.

See also: Microsoft Teams: Bug allows malware delivery

The security issue is identified as CVE-2023-33299 and has received a severity rating of 9.6 out of 10. It is an untrusted data denegotiation that can lead to unauthenticated remote code execution (RCE).

The products affected by this bug are:

  • FortiNAC version 9.4.0 to 9.4.2
  • FortiNAC version 9.2.0 to 9.2.7
  • FortiNAC version 9.1.0 to 9.1.9
  • FortiNAC version 7.2.0 to 7.2.1
  • FortiNAC 8.8, all versions
  • FortiNAC 8.7, all versions
  • FortiNAC 8.6, all versions
  • FortiNAC 8.5, all versions
  • FortiNAC 8.3, all versions

The recommended versions to which you should upgrade to address the risk posed by the vulnerability are as follows:

  • FortiNAC 9.4.3 or above
  • FortiNAC 9.2.8 or above
  • FortiNAC 9.1.10 or above
  • FortiNAC 7.2.2 or above

The vendor has not provided mitigation advice, so the recommended action is to apply the available security updates.

CVE-2023-33299 was discovered by Florian Hauser of Code White, a company that provides Red Team, penetration testing, and threat intelligence services.

Along with the critical RCE, Fortinet also announced today that it has fixed a moderate severity vulnerability tracked as CVE-2023-33300 – an improper access control issue affecting FortiNAC 9.4.0 to 9.4.3 and FortiNAC 7.2.0 to 7.2.1.

The lower severity is indicated by the fact that CVE-2023-33300 can be exploited locally by an attacker with high enough privileges to gain access to the copied data.

Fortinet fixes critical FortiNAC remote command execution bug

Because of the level of access and control over the network, Fortinet products have been particularly attractive to hackers. In recent years, Fortinet devices have been a target for various threat actors, who have breached organizations with zero-day exploits and exploited unpatched devices.

See also: Mirai botnet: Targets 22 vulnerabilities in D-Link, Zyxel, Netgear devices

A recent example is CVE-2022-39952, a critical RCE affecting FortiNAC, which was patched in mid-February, but hackers began using it in attacks a few days later, after the proof-of-concept code was published.

In January, Fortinet warned that threat actors had exploited a vulnerability in FortiOS SSL-VPN (CVE-2022-42475) in attacks against government organizations before the patch was released.

Last year, in October, the company urged customers to patch devices against a critical authentication bypass in FortiOS, FortiProxy, and FortiSwitchManager (CVE-2022-40684) because hackers had begun exploiting it.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS