{"id":4965,"date":"2023-06-18T22:10:22","date_gmt":"2023-06-18T20:10:22","guid":{"rendered":"https:\/\/sajberinfo.com\/?p=4965"},"modified":"2023-06-18T22:10:22","modified_gmt":"2023-06-18T20:10:22","slug":"fortinet-cve-2023-27997","status":"publish","type":"post","link":"http:\/\/sajberinfo.com\/en\/2023\/06\/18\/fortinet-cve-2023-27997\/","title":{"rendered":"Fortinet CVE-2023-27997"},"content":{"rendered":"<p><span style=\"font-size: 14pt;\">Kompanija <em>Fortinet<\/em>\u00a0 je objavila sigurnosna a\u017euriranja a novu kriti\u010dnu ranjivost koja uti\u010de na <em>Fortigate<\/em> <em>SSL<\/em>&#8211;<em>VPN<\/em> mre\u017ene barijere (eng. <em>firewalls<\/em>) koji rade na <em>FortiOS<\/em> ili <em>FortiProxy<\/em> platformama. Proizvo\u0111a\u010d jo\u0161 uvijek nije objavio detaljne informacije o prirodi ranjivosti <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-27997\" target=\"_blank\" rel=\"noopener\">CVE-2023-27997<\/a> \/ FG-IR-23-097, ali je ona dobila <em>CVSSv3<\/em> ocjenu <em>9.2<\/em> i ozna\u010dena je kao ranjivost za neovla\u0161teno daljinsko izvr\u0161avanje k\u00f4da (eng. <em>remote code execution \u2013 RCE<\/em>) na osnovu prelivanja me\u0111uspremnika (eng. <em>buffer overflow<\/em>). Primjetno je da \u010dak ni autentifikacija u dva koraka ne poma\u017ee u ubla\u017eavanju ove ranjivosti.<\/span><\/p>\n<div id=\"attachment_4968\" style=\"width: 1090px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4968\" class=\"size-full wp-image-4968\" src=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/06\/fortinet-cve.jpg\" alt=\"fortinet cve\" width=\"1080\" height=\"600\" srcset=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/06\/fortinet-cve.jpg 1080w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/06\/fortinet-cve-300x167.jpg 300w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/06\/fortinet-cve-1024x569.jpg 1024w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/06\/fortinet-cve-768x427.jpg 768w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/06\/fortinet-cve-18x10.jpg 18w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/><p id=\"caption-attachment-4968\" class=\"wp-caption-text\"><em>Fortinet CVE-2023-27997; Desing by: Sa\u0161a \u0110uri\u0107<\/em><\/p><\/div>\n<h2><strong><span style=\"font-size: 14pt;\">Uticaj ranjivosti<\/span><\/strong><\/h2>\n<p><span style=\"font-size: 14pt;\">Po dostupnim informacijama preko 200.000 ure\u0111aja je dostupno na Internetu i vjerovatno ranjivo. Uz izvje\u0161taje koji ukazuju da je ova ranjivost mo\u017eda ve\u0107 iskori\u0161tava u ograni\u010denom broju slu\u010dajeva, vjerovatno\u0107a dalje zloupotrebe je i dalje velika. Po informacijama dobijenim od proizvo\u0111a\u010da, sljede\u0107e verzije <em>FortiOS<\/em> i <em>FortiProxy<\/em> ure\u0111aja su pogo\u0111ene:<\/span><\/p>\n<p>&nbsp;<\/p>\n<table style=\"width: 100%; height: 726px;\" width=\"100%\">\n<tbody>\n<tr style=\"height: 60px;\">\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><strong>FortiOS-6K7K<\/strong><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><strong>FortiOS<\/strong><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><strong>FortiOS<\/strong><\/span><\/td>\n<\/tr>\n<tr style=\"height: 56px;\">\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 7.0.10<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.0.10<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiProxy verzija 7.2.0 do 7.2.3<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 56px;\">\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 7.0.10<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS verzija 7.2.0 do 7.2.4<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiProxy verzija 7.0.0 do 7.0.9<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 56px;\">\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.4.12<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS verzija 7.0.0 do 7.0.11<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiProxy verzija 2.0.0 do 2.0.12<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 56px;\">\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.4.10<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS verzija 6.4.0 do 6.4.12<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiProxy 1.2 sve verzije<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 56px;\">\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.4.8<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS verzija 6.2.0 do 6.2.13<\/em><\/span><\/td>\n<td style=\"height: 56px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiProxy 1.2 sve verzije<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 60px;\">\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.4.6<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS verzija 6.0.0 do 6.0.16 <\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 60px;\">\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.4.2<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 60px;\">\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.2.9 do 6.2.13<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 60px;\">\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.2.6 do 6.2.7<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 60px;\">\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.2.4<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<\/tr>\n<tr style=\"height: 60px;\">\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 12pt;\"><em>FortiOS-6K7K verzija 6.0.12 do 6.0.16 <\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<td style=\"height: 60px;\" width=\"236\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 14pt;\">Ranjivost <em>CVE-2023-27997<\/em> je otkrivena tokom revizije k\u00f4da <em>SSL-VPN<\/em> modula nakon jo\u0161 jednog nedavnog skupa napada na vladine organizacije gdje je iskori\u0161tavana ranjivost nultog dana <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2022-42475\" target=\"_blank\" rel=\"noopener\"><em>CVE-2022-42475<\/em><\/a> u <em>FortiOS SSL-VPN <\/em>ure\u0111ajima<em>.<\/em><\/span><\/p>\n<p><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><\/p>\n<blockquote><p><span style=\"font-size: 14pt;\"><em>\u201cNa\u0161a istraga je otkrila da je jedan problem (FG-IR-23-097) mo\u017eda iskori\u0161tavan u ograni\u010denom broju slu\u010dajeva i mi blisko sara\u0111ujemo sa kupcima kako bismo pratili situaciju. Iz tog razloga, ako je korisniku omogu\u0107en SSL-VPN, Fortinet savjetuje klijente da odmah preduzmu mjere za nadogradnju na najnoviju verziju upravlja\u010dkog softvera. Ako korisnik ne koristi SSL-VPN, rizik od ovog problema je smanjen \u2013 me\u0111utim, Fortinet i dalje preporu\u010duje nadogradnju.\u201d<\/em><\/span><\/p>\n<p style=\"text-align: right;\"><span style=\"font-size: 14pt;\"><em>\u00a0<\/em><\/span><span style=\"font-size: 14pt;\"><em>&#8211; <\/em><a href=\"https:\/\/www.fortinet.com\/blog\/psirt-blogs\/analysis-of-cve-2023-27997-and-clarifications-on-volt-typhoon-campaign\" target=\"_blank\" rel=\"noopener\"><em>Fortinet<\/em><\/a><em> &#8211;<\/em><\/span><\/p>\n<\/blockquote>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-size: 14pt;\"><strong>A\u017euriranje<\/strong><\/span><\/h3>\n<p><span style=\"font-size: 14pt;\">Kompanija <em>Fortinet<\/em> je objavila nova a\u017euriranja upravlja\u010dkog softvera koja popravljaju kriti\u010dnu ranjivost daljinskog izvr\u0161avanja koda pre autentifikacije na <em>SSL<\/em>&#8211;<em>VPN<\/em> ure\u0111ajima, ozna\u010denu kao <em>CVE-2023-27997<\/em>. Bezbjednosne ispravke objavljene su u verzijama upravlja\u010dkog softvera <em>FortiOS<\/em> <em>6.0.17, 6.2.15, 6.4.13, 7.0.12<\/em> i <em>7.2.5<\/em>.<\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Kako bi ubla\u017eili posljedice ove ranjivosti korisnicima se preporu\u010duju sljede\u0107i koraci:<\/span><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li><span style=\"font-size: 14pt;\">A\u017euriranje ure\u0111aja na najnoviju verziju.<\/span><\/li>\n<li><span style=\"font-size: 14pt;\">Ako ure\u0111aj nije mogu\u0107e nadograditi, potrebno je onemogu\u0107iti <em>SSL-VPN<\/em>.<\/span><\/li>\n<li><span style=\"font-size: 14pt;\">Provjeriti okru\u017eenje u potrazi za tragovima iskori\u0161tavanja prethodnih ranjivosti, kao \u0161to je <em><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-377\" target=\"_blank\" rel=\"noopener\">FG-IR-22-377<\/a><\/em> \/ <em><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-40684\" target=\"_blank\" rel=\"noopener\">CVE-2022-40684<\/a>.<\/em><\/span><\/li>\n<li><span style=\"font-size: 14pt;\">Pratiti <a href=\"https:\/\/docs.fortinet.com\/document\/fortigate\/7.2.0\/best-practices\/555436\/hardening\" target=\"_blank\" rel=\"noopener\">uputstvo proizvo\u0111a\u010da<\/a> za primjenu preporu\u010denih bezbjednosnih pode\u0161avanja.<\/span><\/li>\n<li><span style=\"font-size: 14pt;\">Onemogu\u0107iti funkcije ure\u0111aja koje se ne koriste.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h4><span style=\"font-size: 14pt;\"><strong>Zaklju\u010dak<\/strong><\/span><\/h4>\n<p><span style=\"font-size: 14pt;\"><em>Fortinet<\/em> ure\u0111aji su neki od najpopularnijih mre\u017enih barijera i <a href=\"https:\/\/sajberinfo.com\/en\/2021\/10\/17\/vpn-sigurno-mrezno-povezivanje\/\" target=\"_blank\" rel=\"nofollow noopener\"><em>VPN<\/em><\/a> ure\u0111aja na tr\u017ei\u0161tu, \u0161to ih \u010dini popularnom metom za napade, zbog toga administratori moraju primijeniti bezbjednosna a\u017euriranja \u010dim postanu dostupna. Iako nije dostupno puno informacija, ranjivost za neovla\u0161teno daljinsko izvr\u0161avanje k\u00f4da predstavlja zna\u010dajan rizik za preko 200.000 izlo\u017eenih ure\u0111aja. zbog toga bi korisnici trebalo da primjene bezbjednosna a\u017euriranja \u010dim postanu dostupna.<\/span><\/p>","protected":false},"excerpt":{"rendered":"<p>Kompanija Fortinet\u00a0 je objavila sigurnosna a\u017euriranja a novu kriti\u010dnu ranjivost koja uti\u010de na Fortigate SSL&#8211;VPN mre\u017ene barijere (eng. firewalls) koji rade na FortiOS ili FortiProxy platformama. Proizvo\u0111a\u010d jo\u0161 uvijek nije objavio detaljne informacije o&#46;&#46;&#46;<\/p>","protected":false},"author":1,"featured_media":4968,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[427,162,425,285,295,426,424,78],"class_list":["post-4965","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hronike","tag-buffer-overflow","tag-firewall","tag-fortigate","tag-fortinet","tag-fortios","tag-fortiproxy","tag-remote-code-execution-rce","tag-vpn"],"_links":{"self":[{"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts\/4965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/comments?post=4965"}],"version-history":[{"count":0,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts\/4965\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/media\/4968"}],"wp:attachment":[{"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/media?parent=4965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/categories?post=4965"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/tags?post=4965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}