Fortinet firewall vulnerability could give hackers full control
The FBI has issued multiple warnings of hackers using flaws in Fortinet products
Security researchers have discovered a vulnerability in the Fortinet FortiWeb firewall that could let an attacker take full control of the security device. This vulnerability, assigned CVE-2021-22123 and a CVSSv3 score of 7.4, is highly dangerous.
According to Andrey Medov, the researcher at Positive Technologies who discovered the bug, a command injection vulnerability exists in the FortiWeb management interface that may allow authenticated remote attackers to execute arbitrary commands in the system via the SAML server configuration page. Executing commands with maximum privileges will give the attacker full control over the server.
“If, as a result of incorrect configuration, the firewall administration interface is available on the Internet, and the product itself is not updated to the latest versions, then the combination of CVE-2021-22123 and CVE-2020-29015 that Positive Technologies discovered earlier may allow an attacker to penetrate the internal network,” he said.
The vendor issued a security advisory patching the flaw last month. To fix the vulnerability, update FortiWeb 6.3.7 (and earlier), 6.2.3 (and earlier), 6.1.x, 6.0.x, or 5.9.x to versions 6.3.8 or 6.2.4, depending on the build used.
The secure cloud configuration imperative
The central role of cloud security posture managementFree download
"The APT actors likely created an account with the username 'elie' to further enable malicious activity on the network," according to the Feds.
While the FBI did not say which local government was hacked, it has issued multiple warnings of hackers using flaws in Fortinet products.
“The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) previously warned in April 2021 that APT actors had gained access to devices on ports 4443, 8443, and 10443 for Fortinet FortiOS CVE-2018-13379, and enumerated devices for FortiOS CVE-2020- 12812 and FortiOS CVE-2019-5591,” the flash notice read.
The FBI added that APT actors can leverage their access to conduct data exfiltration, data encryption, or other malicious activity.
“The APT actors are actively targeting a broad range of victims across multiple sectors, indicating the activity is focused on exploiting vulnerabilities rather than targeted at specific sectors,” the FBI warned.
Organizations using these products should update them as soon as possible.
What 2023 will mean for the industry
What do most IT decision makers really think will be the important trends and challenges in the coming year?Free Download
2022 Magic quadrant for Security Information and Event Management (SIEM)
SIEM is evolving into a security platform with multiple features and deployment modelsFree Download
IDC MarketScape: Worldwide unified endpoint management services
2022 vendor assessmentFree Download
Magic quadrant for application performance monitoring and observability
Enabling continuous updating of diverse & dynamic application environmentsView Now