Database/Control plane, storage & DevOps
Fortinet FortiOS / FortiProxy SSL-VPN: A heap-based buffer overflow in the SSL-VPN daemon lets a remote
Impact
A heap-based buffer overflow in the SSL-VPN daemon lets a remote, unauthenticated attacker run arbitrary code on the FortiGate — full device compromise. This is the 'XORtigate' bug, confirmed in CISA's KEV catalog as actively exploited; if this FortiGate is the VPN gateway into your cluster's management network, an attacker doesn't need any credentials to get a foothold there.
Who can reach it
Remote, unauthenticated — a specifically crafted request to the SSL-VPN service is sufficient, no login required.
What to do
Firmware upgrade of FortiOS/FortiProxy to the fixed release per Fortinet PSIRT FG-IR-23-097. Given confirmed active exploitation, patch immediately rather than waiting for a scheduled window, and assume compromise on any internet-facing unit that was unpatched during the exploitation window — a reboot alone doesn't remediate a box that was already popped.
References
Related entries
- Progress MOVEit Transfer: Unauthenticated SQL injection into the web appCVE-2023-34362 · Progress MOVEit TransferCritical
- Citrix NetScaler ADC/Gateway: Unauthenticated remote code execution on the gateway applianceCVE-2023-3519 · Citrix NetScaler ADC/GatewayCritical
- JetBrains TeamCity: Authentication bypass leading to remote code execution on TeamCity ServerCVE-2023-42793 · JetBrains TeamCityCritical
- Acronis Cyber Infrastructure: Default passwordsCVE-2023-45249 · Acronis Cyber InfrastructureCritical
- Fortinet FortiClient EMS: Unauthenticated SQL injectionCVE-2023-48788 · Fortinet FortiClient EMSCritical
- Palo Alto PAN-OS: Management web interface authentication bypassCVE-2024-0012 · Palo Alto PAN-OSCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.