Categories
Audio Sources - Full Text Articles

Fortinet urges customers to fix actively exploited FortiOSĀ SSL-VPN bug

Listen to this article

fortinet-logo.jpg?fit=730%2C480&ssl=1

Fortinet fixed an actively exploited FortiOSĀ SSL-VPN flaw that could allow a remote, unauthenticated attacker to execute arbitrary code on devices.

Fortinet urges customers to update their installs to address an actively exploited FortiOSĀ SSL-VPN vulnerability, tracked as CVE-2022-42475, that could be exploited by an unauthenticated, remote attacker to execute arbitrary code on devices.

The CVE-2022-42475 flaw is a heap-based buffer overflow issue that resides in FortiOS sslvpnd.

ā€œA heap-based buffer overflow vulnerability [CWE-122]Ā in FortiOS SSL-VPN may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.ā€ reads the advisory published by the security vendor. ā€œFortinet is aware of an instance whereĀ this vulnerability was exploited in the wild,ā€

Fortinet recommends its customers of checking the following indicators of compromise:

Multiple log entries with:

Logdesc="Application crashed" and msg="[...] application:sslvpnd,[...], Signal 11 received, Backtrace: [...]ā€œ

Presence of the following artifacts in the filesystem:

/data/lib/libips.bak
/data/lib/libgif.so
/data/lib/libiptcp.so
/data/lib/libipudp.so
/data/lib/libjepg.so
/var/.sslvpnconfigbk
/data/etc/wxd.conf
/flash

Connections to suspicious IP addresses from the FortiGate:

188.34.130.40:444
103.131.189.143:30080,30081,30443,20443
192.36.119.61:8443,444
172.247.168.153:8033

The vulnerability was first disclosed by cybersecurity firm Olympe Cyberdefense

Below is the list of affected products:

FortiOS version 7.2.0 through 7.2.2
FortiOS version 7.0.0 through 7.0.8
FortiOS version 6.4.0 through 6.4.10
FortiOS version 6.2.0 through 6.2.11
FortiOS-6K7K version 7.0.0 through 7.0.7
FortiOS-6K7K version 6.4.0 through 6.4.9
FortiOS-6K7K version 6.2.0 through 6.2.11
FortiOS-6K7K version 6.0.0 through 6.0.14

Fortinet addressed the issue with the release of FortiOS 7.2.3.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

PierluigiĀ Paganini

(SecurityAffairs – hacking, CVE-2022-42475)

The post Fortinet urges customers to fix actively exploited FortiOSĀ SSL-VPN bug appeared first on Security Affairs.