techwithmuchiri
  • Home
  • Reviews
  • Smartphones
    • Android
    • Apple
  • How-To
  • Tech Explained
  • Startups
  • Cybersecurity
  • Buying Guides
  • More
    • Legal Tech
    • Opinions
    • Entertainment
No Result
View All Result
  • Home
  • Reviews
  • Smartphones
    • Android
    • Apple
  • How-To
  • Tech Explained
  • Startups
  • Cybersecurity
  • Buying Guides
  • More
    • Legal Tech
    • Opinions
    • Entertainment
No Result
View All Result
techwithmuchiri
Home Cybersecurity

Over 300,000 FortiGate firewalls vulnerable to critical FortiOS RCE bug

Muchiri by Muchiri
July 5, 2023
in Cybersecurity
0
Fortinet
Share on FacebookShare on Twitter

A critical security flaw, identified as CVE-2023-27997, has left hundreds of thousands of FortiGate firewalls vulnerable to attacks. Despite a recent update released by Fortinet to address the issue, offensive security solutions company Bishop Fox reports that over 300,000 devices remain exposed on the public internet.

Jump ahead

  • The Vulnerability and its Severity
  • Fortinet’s Response and Patch Availability
  • Identification and Estimation of Vulnerable Devices
  • Outdated Firmware Amplifies the Risk
  • Demonstration of the Vulnerability
  • Conclusion: Urgent Action Required

The Vulnerability and its Severity

The vulnerability, classified as a remote code execution flaw, scores a severity rating of 9.8 out of 10. It stems from a heap-based buffer overflow problem within FortiOS, the operating system that integrates Fortinet networking components into the vendor’s Security Fabric platform. The flaw allows unauthenticated attackers to remotely execute code on susceptible devices with an exposed SSL VPN interface.

Fortinet’s Response and Patch Availability

Fortinet promptly addressed the vulnerability on June 11, releasing firmware updates for FortiOS versions 6.0.17, 6.2.15, 6.4.13, 7.0.12, and 7.2.5. However, despite the urgent call to patch affected devices, Bishop Fox’s recent findings suggest that a significant number of FortiGate firewalls are still vulnerable to attacks and accessible over the public internet.

Also Read: Snappy: A tool that detects rogue Wi-Fi access points on open networks

Identification and Estimation of Vulnerable Devices

By utilizing the Shodan search engine, Bishop Fox researchers identified devices with exposed SSL VPN interfaces. They specifically targeted appliances that responded with an HTTP header leading to the “/remote/login” endpoint.

FortiGate CVE-2023-27997 been exploited
Shodan query used for finding exposed devices (Bishopfox)

Out of the 489,337 devices discovered, further investigation revealed that 153,414 had been updated to a secure FortiOS version. This indicates that approximately 335,900 FortiGate firewalls remain vulnerable, surpassing previous estimations of 250,000 devices.

FortiGate CVE-2023-27997 been exploited
Calculation logic used for determining vulnerable devices (Bishopfox)

Outdated Firmware Amplifies the Risk

Bishop Fox researchers made an alarming discovery regarding the exposed FortiGate devices. A significant number of them have not received updates in the past eight years, with some still operating on FortiOS 6, which reached end of support on September 29 last year. Consequently, these devices are susceptible to multiple critical-severity vulnerabilities for which proof-of-concept exploit code is publicly available.

Demonstration of the Vulnerability

To demonstrate the severity of CVE-2023-27997, Bishop Fox created an exploit that showcases the ability to execute code remotely on vulnerable devices. The exploit efficiently “smashes the heap, connects back to an attacker-controlled server, downloads a BusyBox binary, and opens an interactive shell.” According to Bishop Fox, this exploit demonstrates the vulnerability more effectively and executes faster than previous demonstrations by Lexfo.

Conclusion: Urgent Action Required

The widespread vulnerability in FortiGate firewalls necessitates immediate action from organizations utilizing these devices. Patching affected devices with the latest FortiOS firmware is crucial to mitigate the risk of remote code execution. Neglecting these security measures could expose networks and sensitive data to potential attacks. Stay informed, follow the recommended guidelines, and protect your infrastructure from potential threats.

Join us on Telegram
Tags: CVE-2023-27997FortiGateFortinet
Previous Post

Snappy: A tool that detects rogue Wi-Fi access points on open networks

Next Post

Best Twitter alternatives to try out now

Muchiri

Muchiri

Tech editor at Tech with Muchiri. I specialize in covering various aspects of technology and reviewing the latest gadgets. If you have any inquiries or wish to contact me, feel free to reach out to me via email: techwithmuchiri@gmail.com

Next Post
Best Twitter alternatives to try out now

Best Twitter alternatives to try out now

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

TechSpot Africa – The Podcast

TechSpot Africa
TechSpot Africa

Listen to the latest insights in the tech space on the TechSpot Africa Podcast, hosted by Nigel Jr. from tech-space.africa and Antony Muchiri of techwithmuchiri.com. Stay ahead in the tech game, tune in now! Subscribe and share!

Listen OnSpotify
Proposed TikTok Ban in Kenya, Starlink in Kenya, World Coin Craze, Samsung’s New Foldables and Nigel’s Interview with Watu Credit
byTechspot Africa

In this episode of the podcast, we discuss the proposed TikTok ban in Kenya, the arrival of Starlink in Kenya, the world coin craze, Samsung's new foldables, and Nigel's interview with Watu Credit.

  • Proposed TikTok Ban in Kenya: The Kenyan government is considering banning TikTok, citing concerns about the app's impact on children and young people. We discuss the pros and cons of this proposal and what it could mean for Kenyans who use TikTok.
  • Starlink in Kenya: Starlink, the satellite internet service from SpaceX, is now available in Kenya. We discuss what this means for Kenyans who have been struggling with unreliable and expensive internet access.
  • World Coin Craze: A new cryptocurrency called World Coin is causing a stir in Kenya. We discuss what World Coin is and why it is so popular among Kenyans.
  • Samsung's New Foldables: Samsung has just released its new foldable smartphones, the Galaxy Z Fold 5 and the Galaxy Z Flip 5. We take a look at these new devices and discuss whether they are worth the high price tag.
  • Nigel's Interview with Watu Credit: Nigel recently interviewed the Country Manager of Watu Credit, a leading asset financing company in Kenya.

We hope you enjoy this episode of the podcast!

Proposed TikTok Ban in Kenya, Starlink in Kenya, World Coin Craze, Samsung’s New Foldables and Nigel’s Interview with Watu Credit
Proposed TikTok Ban in Kenya, Starlink in Kenya, World Coin Craze, Samsung’s New Foldables and Nigel’s Interview with Watu Credit
August 16, 2023
Techspot Africa
Is threads a Threat to Twitter, Nothing Phone (2) First Impressions and is Google’s First attempt at a Foldable a flop?
July 13, 2023
Techspot Africa
Digital Content Creator Tax is a bad idea, Apple Vision Pro is the Future, and Transsion Vs Samsung Vs Others
June 14, 2023
Techspot Africa
Exploring why Samsung S23 Series sales skyrocketing, the upper-budget smartphone influx, and triple folding Samsung tablet rumors.
April 11, 2023
Techspot Africa
EP3: Buying a Refurbished Flagship vs A New Midrange Smartphone and The Tecno Phantom V Fold Shocked us!
March 30, 2023
Techspot Africa
Kenyan Labour is Cheap, Twitter’s 2FA Charge, Facebook’s Paid Verification, OPPO Reno8 T Pricing, and More!
February 21, 2023
Techspot Africa
Google Bard is the ChatGPT Killer? Samsung S23 Pricing in Kenya is Weird and OPPO Reno8t First Impressions
February 7, 2023
Techspot Africa
Search Results placeholder
  • About Us
  • Contact Us
  • Privacy Policy
Email us: techwithmuchiri@gmail.com

© 2023 Tech With Muchiri

No Result
View All Result
  • Home
  • Reviews
  • Smartphones
    • Android
    • Apple
  • How-To
  • Tech Explained
  • Startups
  • Cybersecurity
  • Buying Guides
  • More
    • Legal Tech
    • Opinions
    • Entertainment

© 2023 Tech With Muchiri

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT