HomeSecurityFortinet FortiClient EMS: PoC exploit released for critical vulnerability

Fortinet FortiClient EMS: PoC exploit released for critical vulnerability

Security researchers have released a proof-of-concept (PoC) exploit for a critical vulnerability in Fortinet 's FortiClient Enterprise Management Server (EMS) software .

FortiClient EMS vulnerability

The vulnerability is tracked as CVE-2023-48788 and is a SQL injection bug in the DB2 Administration Server (DAS) component. It affects versions 7.0 (7.0.1 to 7.0.10) and 7.2 (7.2.0 to 7.2.2) of FortiClient EMS. Exploitation allows unauthorized users to perform remote code execution (RCE) with SYSTEM privileges on unpatched servers. No user interaction is required.

When Fortinet first announced the vulnerability in its software , it did not say that it had been used in attacks. But it has now updated the warning to add that “the vulnerability is being exploited.”

See also: Hackers can unlock hotel doors via Unsaflok vulnerabilities

However, the company has been releasing updates security to address the vulnerability since last week.

Now, security researchers from Horizon3's Attack Team have published a technical analysis and shared a proof-of-concept (PoC) exploit that shows whether a system is vulnerable.

Those who want to use the Horizon3 exploit code in RCE attacks must modify the PoC to use the xp_cmdshell to create a Windows command shell for code execution.

"To turn this SQL injection vulnerability into remote code execution we used Microsoft SQL Server's built-in xp_cmdshell function," said researcher James Horseman.

See also: Apple chip vulnerability leaks encryption keys

“Initially, the database was not configured to run the xp_cmdshell command, however it was enabled with some other SQL statements“.

According to Shodan, over 440 FortiClient EMS servers are exposed online ,while service Shadowserver found more than 300 (most in the US).

The above shows that applying the latest updates is critical for the security of systems. Failure to apply Fortinet patches allows attackers to exploit vulnerabilities to cause damage or gain access to sensitive data.

PoC exploit Fortinet

Additionally, failure to apply updates could potentially impact system functionality . Attacks that exploit vulnerabilities can cause serious disruptions, which may include data loss or inability to access services.

In addition to updating FortiClient EMS, it is important to use strong and unique passwords for administrative accounts. This can help prevent account compromise through brute force or dictionary attacks.

See also: Atlassian fixes critical vulnerability in Bamboo Data Center

Using an intrusion protection system (IPS) can also help detect and prevent RCE attacks. systems monitor the network for suspicious activity and can block communication to and from IP addresses known to be involved in RCE attacks.

Finally, implementing the principles of least privilege can reduce the likelihood of a successful RCE attack. This means that users and administrators should only have the privileges they need to perform their tasks and no more.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS