Thousands of Fortinet firewalls face critical authentication flaw
Security researchers claimed more than 10,000 Fortinet firewalls are at risk from a legacy vulnerability affecting FortiGate SSL VPN.
As reported by Bleeding Computer , internet watchdog Shadowserver claimed the firewalls remain unpatched against CVE-2020-12812 , an improper authentication vulnerability first discovered in the Fortinet operating system (OS) back in 2020. The majority of the affected firewalls discovered by Shadowserver are to be found in Asia (5,355), with 1,300 compromised IP addresses traced to the U.S.
The vulnerability allows users to log in without being prompted for second factor authentication (2FA) if they changed the case of their username (for example, jsmith instead of JSmith). Affecting FortiOS versions 6.4.0, 6.2.0 to 6.2.3, and 6.0.9, users were recommended at the time to upgrade to newer versions of the OS.
In 2021, the vulnerability was discovered to be part of various Fortinet exploits being abused by nation-state actors leading to a joint notice between the FBI and the Cybersecurity and Infrastructure Security Agency (CISA).
Fortinet reported before Christmas that it had discovered recent abuse of the flaw due to differences in behavior of lightweight directory access protocol (LDAP) directories in its flagship FortiGate firewall.
"FortiGates can allow LDAP users with 2FA configured to bypass 2FA and instead authenticate against LDAP directly," warned Fortinet CISO Carl Windsor. "Part of what makes this situation possible is the misconfiguration of a secondary LDAP group that is used when the local LDAP authentication fails. If a secondary LDAP group is not required, it should be removed. If no LDAP groups are used at all, no authentication via LDAP group is possible, and the user will fail authentication if the username is not a match to a local entry."
Fortinet advised users yet to deploy FortiOS 6.0.10, 6.2.4, or 6.4.1 should set the command "set username-case-sensitivity disable" on all local accounts. Users of later versions of FortiO2 (v6.0.13, v6.2.10, v6.4.7, and v7.0.1) were recommended to use the "set username-sensitivity disable" command.
"With username-sensitivity set to disabled, FortiGate will treat jsmith, JSmith, JSMITH and all possible combinations as identical and therefore prevent failover to any other misconfigured LDAP group setting," Windsor wrote.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
