Rewterz
Rewterz Threat Alert – LockBit Ransomware – Active IOCs
June 13, 2023
Rewterz
Rewterz Threat Advisory – Multiple Fortinet FortiADC and FortiADC Manager Vulnerabilities
June 13, 2023

Rewterz Threat Advisory – Multiple Fortinet FortiOS, FortiProxy and Fortiweb Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-33305 CVSS:4.9

Fortinet FortiOS, FortiProxy and Fortiweb is vulnerable to a denial of service, caused by an infinite loop flaw. By using a specially crafted firmware image a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2023-41327 CVSS:7.8

Fortinet FortiOS and FortiProxy could allow a local authenticated attacker to obtain sensitive information, caused by the transmission of sensitive information in plain text. By using the diagnose CLI commands to intercept traffic, an attacker could exploit this vulnerability to obtain administrators cookies, and use this information to launch further attacks against the affected system.

CVE-2023-29178 CVSS:4.3

Fortinet FortiOS and FortiProxy are vulnerable to a denial of service, caused by an access of uninitialized pointer flaw in the administrative interface API. By sending specially crafted HTTP or HTTPS requests, a remote authenticated attacker could exploit this vulnerability to cause the httpsd process to crash.

CVE-2023-43953 CVSS:6.7

Fortinet FortiOS and FortiProxy could allow a local authenticated attacker to execute arbitrary code on the system, caused by a format string flaw in the command line interpreter. By sending specially crafted command arguments, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2023-29175 CVSS:4.8

Fortinet FortiOS and FortiProxy is vulnerable to a man-in-the-middle attack, caused by the lack of certificate verification when establishing secure connections with FortiGuard’s map server. An attacker could exploit this vulnerability to launch a man-in-the-middle attack and gain access to the communication channel between endpoints to obtain sensitive information or further compromise the system.

CVE-2023-22639 CVSS:6.7

Fortinet FortiOS and FortiProxy could allow a local authenticated attacker to execute arbitrary code on the system, caused by an out-of-bounds write flaw in the Command Line Interface. By sending specially crafted commands, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Impact

  • Code Execution
  • Denial of Service
  • Information Disclosure
  • Gain Access

Indicators Of Compromise

CVE

  • CVE-2023-33305
  • CVE-2023-41327
  • CVE-2023-29178
  • CVE-2023-43953
  • CVE-2023-29175
  • CVE-2023-22639

Affected Vendors

Fortinet

Affected Products

  • Fortinet FortiWeb 6.3.0
  • Fortinet FortiProxy 2.0.0
  • Fortinet FortiProxy 1.1
  • Fortinet FortiOS 7.0.0
  • Fortinet FortiProxy 1.0
  • Fortinet FortiProxy 7.0.0
  • Fortinet FortiOS 7.2.0
  • Fortinet FortiProxy 7.2.0
  • Fortinet FortiWeb 7.0.0
  • Fortinet FortiProxy 1.2
  • Fortinet FortiOS 6.4.0
  • Fortinet FortiOS 6.2
  • Fortinet FortiOS 6.0
  • Fortinet FortiOS 7.2.3
  • Fortinet FortiProxy 7.2.3
  • Fortinet FortiWeb 6.4
  • Fortinet FortiProxy 7.0.9
  • Fortinet FortiWeb 7.0.6
  • Fortinet FortiWeb 7.2.0
  • Fortinet FortiWeb 7.2.1
  • Fortinet FortiProxy 7.0.7
  • Fortinet FortiProxy 7.2.1
  • Fortinet FortiOS 7.0.8
  • Fortinet FortiOS 7.2.4
  • Fortinet FortiOS 7.0.11
  • Fortinet FortiOS 6.0.0
  • Fortinet FortiOS 6.2.0
  • Fortinet FortiProxy 7.0.8
  • Fortinet FortiProxy 7.2.2
  • Fortinet FortiOS 6.4.12
  • Fortinet FortiOS 7.0.10

Remediation

Refer to FortiGuard Advisory for patch, upgrade or suggested workaround information.

CVE-2023-33305

CVE-2023-41327

CVE-2023-29178

CVE-2023-43953

CVE-2023-29175

CVE-2023-22639