NSA hacking tools: critical security hole in FortiGate firewalls, patch now
Summary
In August 2016 Fortinet closed a critical hole in FortiOS up to version 4.x through which an attacker could gain admin rights remotely with a manipulated HTTP request. Shortly before, the group Shadow Brokers had published tools of the Equation Group, including exploits for FortiGate firewalls. Fortinet did not name the leak as the reason, but a connection seemed likely.
Ideas
- Leaked intelligence tools became a threat to all operators of affected devices.
- Even outdated version branches still received fixes.
- The hole could be exploited via the firewall’s web interface.
Insights
- Withheld vulnerabilities endanger everyone as soon as the tools fall into the wrong hands.
- Security devices at the network edge are themselves preferred targets.
Facts
- The fixed versions were 4.1.11, 4.2.13 and 4.3.9 as well as the 5.x branch.
- Shortly before, Cisco had also published patches for its own firewalls.
References
Critique
- The information on the authentication required remains contradictory and makes assessing the risk harder.
Recommendations
- Never make the management interface of firewalls reachable from the internet.
- Run security devices on supported version branches instead of old versions.
Links to the original source and the Web Archive open in a new tab.