Saturday, November 16, 2024
HomeCyber security CourseFortiOS SSL-VPN Zero-day Flaw Exploited to Attack Government Organizations

FortiOS SSL-VPN Zero-day Flaw Exploited to Attack Government Organizations

Published on

There have been a number of attacks against government organizations and government-related targets using FortiOS SSL-VPN zero-day vulnerabilities patched by Fortinet last month that have been exploited by unknown attackers.

A security flaw (CVE-2022-42475) was exploited in these incidents to empower attackers to gain remote code execution and crash targeted devices remotely.

This vulnerability can be attributed to a heap-based buffer overflow found in the FortiOS SSLVPNd application.

- Advertisement - SIEM as a Service

The network security company quietly fixed the bug on November 28th by releasing a new version (7.2.3) of the software that addressed the vulnerability. 

While in mid-December, the company urged its customers to download and install this patch to protect against the ongoing attacks that were exploiting the vulnerability without making noise.

The network security company first informed their customers about the vulnerability through a TLP: Amber advisory on the 7th of December, a confidential notification meant for restricted distribution. 

They later made additional information about the vulnerability available to the public on December 12, along with an alert that the vulnerability was being actively exploited and targeted by attackers in ongoing attacks.

Products Affected By Vulnerability

Here below we have mentioned the complete list of affected products:-

  • FortiOS version 7.2.0 through 7.2.2
  • FortiOS version 7.0.0 through 7.0.8
  • FortiOS version 6.4.0 through 6.4.10
  • FortiOS version 6.2.0 through 6.2.11
  • FortiOS version 6.0.0 through 6.0.15
  • FortiOS version 5.6.0 through 5.6.14
  • FortiOS version 5.4.0 through 5.4.13
  • FortiOS version 5.2.0 through 5.2.15
  • FortiOS version 5.0.0 through 5.0.14
  • FortiOS-6K7K version 7.0.0 through 7.0.7
  • FortiOS-6K7K version 6.4.0 through 6.4.9
  • FortiOS-6K7K version 6.2.0 through 6.2.11
  • FortiOS-6K7K version 6.0.0 through 6.0.14
  • FortiProxy version 7.2.0 through 7.2.1
  • FortiProxy version 7.0.0 through 7.0.7
  • FortiProxy version 2.0.0 through 2.0.11
  • FortiProxy version 1.2.0 through 1.2.13
  • FortiProxy version 1.1.0 through 1.1.6
  • FortiProxy version 1.0.0 through 1.0.7

Abused Zero-day to Target Networks of Government

It was found that the attacks of the threat actor were highly targeted, with the investigation indicating that the priority networks were those of the government.

Upon examination, the Windows sample linked to the attacker exhibited signs of being constructed on a computer in the UTC+8 timezone. This timezone encompasses various countries such as:- 

  • Australia
  • China
  • Russia
  • Singapore
  • Other Eastern Asian countries

They are suggesting that the attacker may be located in one of these regions. However, it’s important to note that this information is not definitive proof of the attacker’s location.

In order to achieve long-term access to the network, malicious actors focused heavily on avoiding detection. 

They leveraged the vulnerability to install malware that modifies FortiOS logging processes to delete specific logs or stop logging altogether, in order to conceal their activities.

There are the following artifacts present in the file system:-

  • /data/lib/libips.bak
  • /data/lib/libgif.so
  • /data/lib/libiptcp.so
  • /data/lib/libipudp.so
  • /data/lib/libjepg.so
  • /var/.sslvpnconfigbk
  • /data/etc/wxd.conf
  • /flash

According to further analyses of the malware installed on compromised appliances, malicious payloads included in the malware also disrupted the security violation detection capability of the compromised devices’ IPS, which constantly monitors network traffic to detect threats and block them whenever security breaches take place.

Solutions

Here below we have mentioned the available solutions:-

  • Please upgrade to FortiOS version 7.2.3 or above
  • Please upgrade to FortiOS version 7.0.9 or above
  • Please upgrade to FortiOS version 6.4.11 or above
  • Please upgrade to FortiOS version 6.2.12 or above
  • Please upgrade to FortiOS version 6.0.16 or above
  • Please upgrade to upcoming FortiOS-6K7K version 7.0.8 or above
  • Please upgrade to FortiOS-6K7K version 6.4.10 or above
  • Please upgrade to FortiOS-6K7K version 6.2.12 or above
  • Please upgrade to FortiOS-6K7K version 6.0.15 or above
  • Please upgrade to FortiProxy version 7.2.2 or above
  • Please upgrade to FortiProxy version 7.0.8 or above
  • Please upgrade to upcoming FortiProxy version 2.0.12 or above

While for workaround availability, users have to Disable SSL-VPN. In order to protect their systems from attack attempts, Fortinet advises customers to make sure their FortiOS installation is up to date with the latest patch and contact its support team if they discover any IOCs related to attacks that occurred in December.

Network Security Checklist – Download Free E-Book

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Critical TP-Link DHCP Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious...

Chinese SilkSpecter Hackers Attacking Black Friday Shoppers

SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce...

Cybercriminals Launch SEO Poisoning Attack to Lure Shoppers to Fake Online Stores

The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to...

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

New Windows Zero-Day Vulnerability Let Attackers Steal Credentials From Victim’s Machine

A security researcher discovered a vulnerability in Windows theme files in the previous year,...

New AI Tool To Discover 0-Days At Large Scale With A Click Of A Button

Vulnhuntr, a static code analyzer using large language models (LLMs), discovered over a dozen...

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...