Fortinet says hackers exploited critical vulnerability to infect VPN customers

A cake that mimics FortiGate hardware.

Fortinet

An unknown attacker exploited a critical vulnerability in Fortinet’s FortiOS SSL-VPN to infect governments and government-affiliated organizations with sophisticated, custom-made malware, the company said in an autopsy report Wednesday. .

This vulnerability, tracked as CVE-2022-42475, is a heap-based buffer overflow that allows hackers to remotely execute malicious code. Severity is 9.8 out of 10. Network security software maker Fortinet fixed the vulnerability in version 7.2.3, released on November 28, but made no mention of the threat in its release notes published in the United States. time.

mom’s words

Fortinet didn’t disclose the vulnerability until December 12th, but warned that it was being actively exploited against at least one customer. The company confirmed that it was running a patched version of its software and encouraged customers to search their networks for signs that the vulnerability had been exploited. FortiOS SSL-VPN is primarily used at perimeter firewalls to shield sensitive internal networks from the public internet.

On Wednesday, Fortinet provided a detailed description of the exploit activity and the attackers behind it. However, the post didn’t explain why it didn’t disclose the vulnerabilities it fixed in November. A company spokesperson declined to answer an emailed question about the company’s policy on disclosure of failures and vulnerabilities.

“The complexity of the exploit suggests it is by sophisticated actors and highly targeted against government or government-affiliated targets,” Fortinet officials wrote in Wednesday’s update. They continued:

  • Exploitation requires a deep understanding of FortiOS and its underlying hardware.
  • The use of custom implants demonstrates the attacker’s sophistication, including reverse engineering various parts of FortiOS.
  • The attackers are highly targeted and there are some hints that government or government-affiliated targets are preferred.
  • The attacker’s Windows samples discovered exhibited artifacts that were compiled on machines with UTC+8 timezones including Australia, China, Russia, Singapore, and other East Asian countries.
  • All self-signed certificates created by the attackers were created between 3:00 AM and 8:00 AM UTC. However, given that hackers don’t necessarily operate during business hours, they often operate during the victim’s business hours, which helps obfuscate their activity in general network his traffic. , it is difficult to draw any conclusions from this.

Analysis performed by Fortinet on one of the infected servers indicates that the attacker used this vulnerability to install a variant of a known Linux-based implant customized to run on FortiOS. it was done. To avoid detection, the post-exploit malware disabled certain log events once installed. The implant was installed in the /data/lib/libips.bak path. This file is likely masquerading as part of Fortinet’s IPS engine located at /data/lib/libips.so. The file /data/lib/libips.so also existed but had a file size of zero.

After emulating the execution of the implant, Fortinet researchers discovered a unique sequence of bytes in the communication with the command and control server that could be used to sign the intrusion prevention system. Buffer “\x00\x0C\x08http/1.1\x02h2\x00\x00\x00\x14\x00\x12\x00\x00\x0Fwww.example.com” (unescaped) appears in “Client Hello” packet will be

Other signs that a server has been targeted include connections to various IP addresses, including 103.[.]131[.]189[.]143, and the following TCP sessions:

  • Connection to FortiGate on port 443
  • Get requests for /remote/login/lang=en
  • Post request to remote/error
  • Get request to payload
  • Connection to run commands on the FortiGate
  • An interactive shell session.

Autopsy included various other signs of compromise. Organizations using FortiOS SSL-VPN should read this document carefully and inspect their network for signs of being targeted or compromised.

As mentioned above, the autopsy cannot explain why Fortinet did not disclose CVE-2022-42475 until it was actually exploited. The failure is especially serious given the severity of the vulnerability. Disclosure is very important because it helps users prioritize patch installation. When a new version fixes minor bugs, many organizations wait to install it. Fixing vulnerabilities with a severity of 9.8 will likely speed up the update process.

Instead of answering questions about the lack of disclosure, Fortinet officials provided the following statement:

We are committed to your security. In December 2022, Fortinet distributed her PSIRT advisory (FG-IR-22-398). This advisory details mitigations for CVE-2022-42475 and recommends next steps. We have notified our customers through the PSIRT advisory process and advised them to follow the guidance provided. We also encourage you to continue to monitor the situation as part of our ongoing commitment to your security. Today, we shared additional and extended research into CVE-2022-42475. For more information, please visit our blog.

The company said it was unable to obtain additional malicious payloads used in the attack.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *