FortiGate VPN Vulnerability: Hackers Maintain Access Even After Patches
Fortinet has issued an urgent warning to customers that hackers may retain read-only access to compromised FortiGate VPN devices even after security vulnerabilities have been patched. This sophisticated persistence technique leverages symbolic links to maintain unauthorized access, potentially exposing sensitive device configurations and data.
Fortinet’s security team has discovered that attackers exploited previously known vulnerabilities to create a backdoor into affected systems. The attack doesn’t rely on new vulnerabilities but instead uses a clever technique to maintain persistence after initial compromise.
According to Fortinet’s alert: “FortiGuard telemetry shows that in connection with the detection of a malicious file, one or more of your devices could be compromised. This problem is not related to any new vulnerability. The file was left by the attacker after the exploitation of previous known vulnerabilities.”
The company specifically highlighted several CVEs that were likely used in the initial compromise:
The threat actors employed a sophisticated technique to maintain access:
“The attackers used known vulnerabilities to gain read-only access to FortiGate devices. This was achieved by creating a symbolic link connecting the file system related to the user space and the root file system in the language file folder for SSL-VPN,” Fortinet explained. “Since the modification took place in the user file system, the attackers managed to avoid detection.”
While Fortinet didn’t specify the exact timeline of these attacks in their customer notification, the French Computer Emergency Response Team (CERT-FR) reported that this attack technique was part of a large-scale campaign that began in the first half of 2023.
Fortinet strongly urges customers to immediately update their FortiOS to the latest secure versions to eliminate the malicious files used by attackers to maintain access:
Organizations using FortiGate devices should consider these additional security measures:
Fortinet is a global leader in cybersecurity solutions, offering a broad range of security products including firewalls, VPNs, anti-virus, intrusion prevention systems, and endpoint security. The company focuses on providing integrated security solutions for networks, cloud environments, and remote workers. Founded in 2000, Fortinet has become one of the largest cybersecurity vendors worldwide, known for its FortiGate next-generation firewall technology and unified security management approach.
FortiGate and other devices have faced an alarming pattern of critical vulnerabilities in recent years, with this latest symbolic link persistence technique highlighting Fortinet’s ongoing struggle to fully secure their products against sophisticated threat actors who repeatedly find ways to maintain unauthorized access.