Database/Control plane, storage & DevOps
Fortinet FortiOS / FortiProxy SSL-VPN: A heap-based buffer overflow in the SSL-VPN daemon lets a remote
Impact
A heap-based buffer overflow in the SSL-VPN daemon lets a remote, unauthenticated attacker run arbitrary code on the FortiGate — full device compromise. This is the 'XORtigate' bug, confirmed in CISA's KEV catalog as actively exploited; if this FortiGate is the VPN gateway into your cluster's management network, an attacker doesn't need any credentials to get a foothold there.
Who can reach it
Remote, unauthenticated — a specifically crafted request to the SSL-VPN service is sufficient, no login required.
What to do
Firmware upgrade of FortiOS/FortiProxy to the fixed release per Fortinet PSIRT FG-IR-23-097. Given confirmed active exploitation, patch immediately rather than waiting for a scheduled window, and assume compromise on any internet-facing unit that was unpatched during the exploitation window — a reboot alone doesn't remediate a box that was already popped.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.