<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FortiOS Archives - Access42</title>
	<atom:link href="https://access42.nl/tag/fortios/feed/" rel="self" type="application/rss+xml" />
	<link>https://access42.nl/tag/fortios/</link>
	<description>Cybersecurity Made Easy</description>
	<lastBuildDate>Sun, 09 Oct 2022 05:04:00 +0000</lastBuildDate>
	<language>nl-NL</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://access42.nl/wp-content/uploads/2023/11/circle.png</url>
	<title>FortiOS Archives - Access42</title>
	<link>https://access42.nl/tag/fortios/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CVE-2022-40684: Critical Authentication Bypass in FortiOS and FortiProxy</title>
		<link>https://access42.nl/nieuws/cve-2022-40684-critical-authentication-bypass-in-fortios-and-fortiproxy/</link>
					<comments>https://access42.nl/nieuws/cve-2022-40684-critical-authentication-bypass-in-fortios-and-fortiproxy/#respond</comments>
		
		<dc:creator><![CDATA[Ronald]]></dc:creator>
		<pubDate>Sun, 09 Oct 2022 05:04:00 +0000</pubDate>
				<category><![CDATA[Nieuws]]></category>
		<category><![CDATA[admin interface]]></category>
		<category><![CDATA[cve-2022-40684]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[FortiOS]]></category>
		<category><![CDATA[Tenable]]></category>
		<guid isPermaLink="false">https://www.access42.nl/?p=6205</guid>

					<description><![CDATA[<p>Update 09-10-2022 Fortinet heeft in zijn FortiOS- en FortiProxy-producten een kritieke authenticatie-bypass gepatcht die kan leiden tot Administrator toegang. bronnen: Access42, Tenable en Fortinet Achtergrond Op 7 oktober begonnen openbare berichten te circuleren dat Fortinet rechtstreeks met klanten communiceerde over een kritieke kwetsbaarheid in haar FortiOS en FortiProxy producten. Deze kwetsbaarheid, CVE-2022-40684, is inmiddels gepatcht,&#8230;</p>
<p>The post <a href="https://access42.nl/nieuws/cve-2022-40684-critical-authentication-bypass-in-fortios-and-fortiproxy/">CVE-2022-40684: Critical Authentication Bypass in FortiOS and FortiProxy</a> appeared first on <a href="https://access42.nl">Access42</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Update 09-10-2022</strong></p>



<hr class="wp-block-separator has-css-opacity"/>



<p class="wp-block-paragraph">Fortinet heeft in zijn FortiOS- en FortiProxy-producten een kritieke authenticatie-bypass gepatcht die kan leiden tot Administrator toegang.</p>



<p class="wp-block-paragraph"><em>bronnen: Access42, Tenable en Fortinet</em></p>



<h2 class="wp-block-heading">Achtergrond</h2>



<p class="wp-block-paragraph">Op 7 oktober begonnen openbare <a href="https://www.bleepingcomputer.com/news/security/fortinet-warns-admins-to-patch-critical-auth-bypass-bug-immediately/">berichten</a> te <a href="https://twitter.com/GossiTheDog/status/1578327883847589889?s=20&amp;t=bxFTDcZ6dRj4vr5sf-n-nA">circuleren</a> dat Fortinet rechtstreeks met klanten communiceerde over een kritieke kwetsbaarheid in haar <a href="https://www.fortinet.com/products/fortigate/fortios">FortiOS</a> en <a href="https://www.fortinet.com/products/secure-web-gateway/fortiproxy">FortiProxy</a> producten. Deze kwetsbaarheid, CVE-2022-40684, is inmiddels gepatcht, maar Fortinet heeft nog <a href="https://www.tenable.com/blog/cve-2022-40684-critical-authentication-bypass-in-fortios-and-fortiproxy#:~:text=not%20released%20a%20full%20advisory">geen volledige advisory</a> uitgebracht via zijn <a href="https://www.fortiguard.com/psirt">Product Security Incident Response Team</a>.</p>



<p class="wp-block-paragraph">Fortinet volgt gewoonlijk een maandelijks releaseschema voor beveiligingsadviezen op de tweede dinsdag van elke maand, dezelfde dag als Microsoft&#8217;s Patch Tuesday. Het valt nog te bezien of het hetzelfde schema zal volgen voor de CVE-2022-40684 advisory. De volgende tweet bevat een afbeelding uit de e-mailcommunicatie die naar Fortinet-klanten is gestuurd.</p>



<figure class="wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter"><div class="wp-block-embed__wrapper">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">Update: By now the full text of the e-mail and a screenshot of the internal advisory have been shared.<br>So here goes a screenshot of the unredacted full e-mail as shared on Facebook. Also containing possible <a href="https://twitter.com/hashtag/workarounds?src=hash&amp;ref_src=twsrc%5Etfw">#workarounds</a>.<a href="https://twitter.com/hashtag/Fortinet?src=hash&amp;ref_src=twsrc%5Etfw">#Fortinet</a> <a href="https://twitter.com/hashtag/CVE202240684?src=hash&amp;ref_src=twsrc%5Etfw">#CVE202240684</a> <a href="https://twitter.com/hashtag/RCE?src=hash&amp;ref_src=twsrc%5Etfw">#RCE</a> <a href="https://twitter.com/hashtag/authbypass?src=hash&amp;ref_src=twsrc%5Etfw">#authbypass</a> <a href="https://twitter.com/hashtag/advisory?src=hash&amp;ref_src=twsrc%5Etfw">#advisory</a> <a href="https://t.co/ruVmYhyXA5">pic.twitter.com/ruVmYhyXA5</a></p>&mdash; Gi7w0rm (@Gi7w0rm) <a href="https://twitter.com/Gi7w0rm/status/1578398457227878407?ref_src=twsrc%5Etfw">October 7, 2022</a></blockquote><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</div></figure>



<h2 class="wp-block-heading">Analyse</h2>



<p class="wp-block-paragraph"><a href="https://www.tenable.com/cve/CVE-2022-40684">CVE-2022-40684</a> is een kwetsbaarheid voor het omzeilen van de authenticatie die een CVSSv3-score van 9,6 heeft gekregen. Door speciaal ontworpen HTTP- of HTTPS-verzoeken naar een kwetsbaar doel te sturen, kan een aanvaller op afstand met toegang tot de beheer interface beheerdertaken uitvoeren.</p>



<p class="wp-block-paragraph">Op dit moment is er geen informatie over of deze kwetsbaarheid is uitgebuit in aanvallen. Maar gezien de <a href="https://www.ic3.gov/Media/News/2021/210402.pdf">voorliefde van aanvallers voor FortiOS-kwetsbaarheden</a> is de aanbeveling van Fortinet om deze kwetsbaarheid &#8220;met de grootst mogelijke urgentie&#8221; te verhelpen op zijn plaats.</p>



<h2 class="wp-block-heading">Oplossing</h2>



<p class="wp-block-paragraph">De communicatie die Fortinet naar klanten heeft gestuurd en die nu publiekelijk is gedeeld op Twitter, schetst de volgende kwetsbare en gerepareerde versienummers:<a href="https://www.ncsc.nl/actueel/advisory?id=NCSC-2022-0250"></a></p>



<figure class="wp-block-table"><table><thead><tr><th>Product</th><th>Vulnerable Versions</th><th>Fixed Version</th></tr><tr><td>FortiOS</td><td>7.0.0 to 7.0.67.2.0 to 7.2.1</td><td>7.0.77.2.2</td></tr><tr><td>FortiProxy</td><td>7.0.0 to 7.0.67.2.0</td><td>7.0.77.2.1</td></tr></thead></table></figure>



<p class="wp-block-paragraph">Als u de patches niet onmiddellijk kunt toepassen, stelt Fortinet dat het gebruik van een local-in-policy de toegang tot de beheerinterface moet beperken. Fortinet heeft in hun <a href="https://docs.fortinet.com/document/fortigate/6.0.0/hardening-your-fortigate/582009/system-administrator-best-practices">FortiGate Hardening</a> Guide ook stappen voor het uitschakelen van administratieve toegang tot de internet interface en stappen voor het beperken van de toegang tot vertrouwde hosts. Zoals de whitepaper opmerkt, maken deze stappen deel uit van hun best practices voor systeembeheerders.</p>



<h2 class="wp-block-heading">Identificeren van kwetsbare systemen</h2>



<p class="wp-block-paragraph">Een lijst van Tenable-plugins die deze kwetsbaarheid identificeren, verschijnt <a href="https://www.tenable.com/plugins/search?q=cves%3A%28%22CVE-2022-40864%22%29&amp;sort=&amp;page=1">hier</a> zodra ze zijn vrijgegeven. Deze link maakt gebruik van een zoekfilter om ervoor te zorgen dat alle overeenkomende plugins verschijnen zodra ze zijn vrijgegeven. Klanten kunnen ook Plugin ID <a href="https://www.tenable.com/plugins/nessus/73522">73522</a> gebruiken om de versie van Fortinet Devices in uw netwerk te identificeren. De plugin vereist dat u SSH-referenties opgeeft voor het Fortinet-apparaat.</p>



<h2 class="wp-block-heading">Meer informatie</h2>



<ul class="wp-block-list"><li><a href="https://docs.fortinet.com/document/fortigate/7.2.2/fortios-release-notes/289806/resolved-issues">FortiOS release notes for 7.2.2</a></li><li><a href="https://docs.fortinet.com/document/fortigate/7.0.7/fortios-release-notes/289806/resolved-issues">FortiOS release notes for 7.0.7</a></li><li><a href="https://www.fortiguard.com/psirt">Fortinet PSIRT</a></li></ul>
<p>The post <a href="https://access42.nl/nieuws/cve-2022-40684-critical-authentication-bypass-in-fortios-and-fortiproxy/">CVE-2022-40684: Critical Authentication Bypass in FortiOS and FortiProxy</a> appeared first on <a href="https://access42.nl">Access42</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://access42.nl/nieuws/cve-2022-40684-critical-authentication-bypass-in-fortios-and-fortiproxy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
