Network security solutions provider Fortinet has patched a critical bug in its FortiOS and FortiProxy SSL-VPN software that could be exploited to hijack devices.
This vulnerability, identified as CVE-2023-27997 with a CVSS score of 9.2, could allow remote code execution and was first reportedly discovered by Lexfo’s security analysts.
Security fixes are included in FortiOS firmware versions 6.0.17, 6.2.15, 6.4.13, 7.0.12, and 7.2.5.
Read more about Fortinet vulnerabilities: Organizations urged to address critical vulnerabilities discovered in the first half of 2023
Interestingly, the release notes did not originally mention the critical SSL-VPN RCE vulnerability being addressed. However, security professionals and administrators Including Lexfo’s Charles Folhinted that these updates silently addressed a flaw that was scheduled to go live on June 13, 2023.
Writing on Twitter on Monday, Fol revealed that the latest FortiOS update includes a fix for a critical RCE vulnerability. Rioru had discovered.
“Fortinet has had to respond to many recent vulnerabilities and this is another great example,” said Mike Parkin, senior technical engineer at Vulcan Cyber.
Security experts say it’s not uncommon for patches to be released to address vulnerabilities before they’re publicly acknowledged.
At this time, it remains unclear whether this vulnerability has been exploited in an actual attack or whether knowledge of this vulnerability has spread beyond initial research findings.
“Researchers have been able to produce proofs of concept, but that doesn’t necessarily lead to weaponized exploits,” Parkin added.
“However, once the PoC is over, [Proof of Concept] be published […] Attackers will try to create their own attacks to take advantage of exploits, so Fortinet users should patch their systems as soon as they become available. ”
Another PoC was released last week by Vulcan Cyber regarding a new technique using ChatGPT as an attack vector.
Editorial image credit: T. Schneider / Shutterstock.com