CERT-In Vulnerability Note
CIVN-2021-0257
Multiple vulnerabilities in Fortinet Devices
Original Issue Date:October 12, 2021
Severity Rating: HIGH
Systems Affected
- FortiSDNConnector version 1.1.7 or below.
- FortiAuthenticator 6.3.0 and below.
- FortiAuthenticator 6.2.1 and below.
- FortiAuthenticator 6.2.0 and below.
- FortiWebManager version 6.2.3 and below.
- FortiWebManager version 6.0.x.
- FortiSandbox 4.0.0.
- FortiSandbox 3.2.2 and below.
- FortiSandbox 3.1.4 and below.
- FortiClientEMS version 6.4.1 and below.
- FortiClientEMS version 6.2.8 and below.
- FortiManager version 7.0.0.
- FortiManager versions 6.4.6 and below.
- FortiAnalyzer version 7.0.0.
- FortiAnalyzer versions 6.4.6 and below.
Overview
Multiple vulnerabilities have been reported in Fortinet Devices could allow an attacker to escalate privileges, execute remote code, perform directory traversal and disclose sensitive information on the targeted system.
Description
1. Information disclosure Vulnerability
(
CVE-2021-36178
)
This vulnerability exists in Fortinet Devices due to insecure credentials handling. An attacker can exploit this vulnerability by visiting the configuration page in the WebUI. Successful exploitation of this vulnerability could allow the attacker to obtain third party device credentials.
2. Privilege Escalation Vulnerability
(
CVE-2021-26116
)
This vulnerability exists in Fortinet Devices due to improper input validation in the command line interpreter of FortiAuthenticator. An attacker can exploit this vulnerability by executing unauthorized commands via specifically crafted arguments to existing commands. Successful exploitation of this vulnerability could allow the attacker to escalate privileges on the system.
3. Cross-site scripting Vulnerability
(
CVE-2021-36175
)
This vulnerability exists in Fortinet Devices due to insufficient sanitization of user-supplied data passed via the name/description/comments parameter of various sections of the device. A remote attacker can exploit this vulnerability by injecting and executing arbitrary HTML and script code in users browser in context of vulnerable website. Successful exploitation of this vulnerability could allow the attacker to perform cross-site scripting (XSS) attacks.
4. Stack-based buffer overflow Vulnerability
(
CVE-2021-26105
)
This vulnerability exists in Fortinet Devices due to a stack-based buffer overflow vulnerability in the profile parser of FortiSandbox when processing HTTP requests. An authenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the target system.
5. Path traversal vulnerability
(
CVE-2021-15941
)
This vulnerability exists in Fortinet Devices due to input validation error when processing directory traversal sequences in the name parameter. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request. Successful exploitation of this vulnerability could allow the attacker to add or delete files on the server.
6. Information disclosure Vulnerability
(
CVE-2021-36170
)
This vulnerability exists in Fortinet Devices due to excessive data output by the application. Successful exploitation of this vulnerability could allow the attacker to read the FortiCloud credentials which were used to activate the trial license in cleartext.
Solution
Upgrade to latest version as mentioned in
https://www.fortiguard.com/psirt/FG-IR-20-183
https://www.fortiguard.com/psirt/FG-IR-21-068
https://www.fortiguard.com/psirt/FG-IR-20-027
https://www.fortiguard.com/psirt/FG-IR-20-234
https://www.fortiguard.com/psirt/FG-IR-20-074
https://www.fortiguard.com/psirt/FG-IR-21-112
Vendor Information
Fortiguard
https://www.fortiguard.com/psirt/FG-IR-20-183
https://www.fortiguard.com/psirt/FG-IR-21-068
https://www.fortiguard.com/psirt/FG-IR-20-027
https://www.fortiguard.com/psirt/FG-IR-20-234
https://www.fortiguard.com/psirt/FG-IR-20-074
https://www.fortiguard.com/psirt/FG-IR-21-112
References
Fortiguard
https://www.fortiguard.com/psirt/FG-IR-20-183
https://www.fortiguard.com/psirt/FG-IR-21-068
https://www.fortiguard.com/psirt/FG-IR-20-027
https://www.fortiguard.com/psirt/FG-IR-20-234
https://www.fortiguard.com/psirt/FG-IR-20-074
https://www.fortiguard.com/psirt/FG-IR-21-112
CVE Name
CVE-2021-36178
CVE-2021-26116
CVE-2021-36175
CVE-2021-26105
CVE-2021-15941
CVE-2021-36170
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|