Fortinet warnt vor FortiWLM-Bug, der Hackern Admin-Rechte verleiht

Teilen:

Fortinet has disclosed a critical vulnerability in Fortinet Wireless Manager (FortiWLM) that allows remote attackers to take over devices by executing unauthorized code or commands through specially crafted web requests.

FortiWLM is a centralized management tool for monitoring, managing, and optimizing wireless networks. It’s used by government agencies, healthcare organizations, educational institutions, and large enterprises.

The flaw, tracked as CVE-2023-34990, is a relative path traversal flaw rated with a score of 9.8.

Horizon3 researcher Zach Hanley discovered and disclosed the vulnerability to Fortinet in May 2023. However, the flaw remained unfixed ten months later, and Hanley decided to disclose information and a POC it on March 14, 2024 in a technical writeup about other Fortinet flaws he discovered.

Stealing Admin session IDs
The issue allows unauthenticated attackers to exploit improper input validation in the ‘/ems/cgi-bin/ezrf_lighttpd.cgi’ endpoint.

By using directory traversal techniques in the ‘imagename’ parameter when the ‘op_type’ is set to ‘upgradelogs,’ attackers can read sensitive log files from the system.

These logs often contain administrator session IDs, which can be used to hijack admin sessions and gain privileged access, allowing threat actors to take over devices.

“Abusing the lack of input validation, an attacker can construct a request where the imagename parameter contains a path traversal, allowing the attacker to read any log file on the system,” explained Hanley.

“Luckily for an attacker, the FortiWLM has very verbose logs – and logs the session ID of all authenticated users. Abusing the above arbitrary log file read, an attacker can now obtain the session ID of a user and login and also abuse authenticated endpoints.”

The flaw affects FortiWLM versions 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4.

Despite the researcher’s public warning, the lack of a CVE ID (at the time) and a security bulletin meant that users were unaware of the risk and needed to upgrade to a safe version.

According to the security bulletin Fortinet published yesterday, on December 18, 2024, CVE-2023-34990 was fixed in FortiWLM versions 8.6.6 and 8.5.5, released at the end of September 2023.

CVE-2023-34990 was a zero-day vulnerability for roughly four months, with FortiWLM users first learning about it 10 months after its discovery in Hanley’s writeup. However, it took Fortinet an additional 9 months to release a public security bulletin.

Given its deployment in critical environments, FortiWLM can be a valuable target for attackers, as compromising it remotely could lead to network-wide disruptions and sensitive data exposure.

Therefore, it is strongly advised that FortiWLM admins apply all available updates as they become available.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:21 am, März 14, 2025
Wetter-Symbol 5°C
L: 4° | H: 7°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 84 %
Druck: 1011 mb
Wind: 3 mph E
Windböe: 8 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 50%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:16 am
Sonnenuntergang: 6:02 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
4° | 7°°C 0.86 mm 86% 7 mph 79 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
1° | 8°°C 0.2 mm 20% 12 mph 93 % 1025 mb 0 mm/h
So. März 16 9:00 pm
Wetter-Symbol
1° | 8°°C 0 mm 0% 9 mph 90 % 1027 mb 0 mm/h
Mo. März 17 9:00 pm
Wetter-Symbol
4° | 7°°C 0 mm 0% 13 mph 92 % 1028 mb 0 mm/h
Di. März 18 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 12 mph 78 % 1027 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 6 mph 79 % 1011 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 0.69 mm 69% 7 mph 75 % 1012 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0.86 mm 86% 5 mph 71 % 1014 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 5 mph 77 % 1017 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 80 % 1019 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 5 mph 87 % 1020 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
1° | 1°°C 0 mm 0% 6 mph 93 % 1021 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 8 mph 78 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€76,166.19
-0.78%
Ethereum(ETH)
€1,741.69
-0.02%
Fesseln(USDT)
€0.92
0.00%
XRP(XRP)
€2.13
1.81%
Solana(SOL)
€115.45
-1.48%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.155231
-1.86%
Shiba Inu(SHIB)
€0.000012
2.47%
Pepe(PEPE)
€0.000006
-5.28%
Nach oben scrollen