Skip to main content
Ivar
New Member
December 10, 2021
Solved

CVE-2021-44228 Apache LOG4J vulnerability

  • December 10, 2021
  • 15 replies
  • 94696 views

Would appreciate a response from Fortinet regarding the Apache log4 vulnerability if any Fortinet product

is affected.

 

Any information regarding updated IPS signature for CVE-2021-44228?

Best answer by Carl_Windsor_FTNT

PSIRT advisory on impacted products can be found here:

 

https://www.fortiguard.com/psirt/FG-IR-21-245

15 replies

Carl_Windsor_FTNT
Staff
Staff
December 13, 2021

PSIRT advisory on impacted products can be found here:

 

https://www.fortiguard.com/psirt/FG-IR-21-245

Deepak_Girimaji_FTNT
Staff
Staff
December 13, 2021

For FortiWEB, there is a new update for the WAF signatures to prevent attackers from performing variant remote code execution in Apache Log4j2 (CVE-2021-44228)
Reference: https://www.fortiguard.com/updates/websecurity?version=0.00306

 

 

Deepak_Girimaji_FTNT
Staff
Staff
December 13, 2021

There is a new update for the WAF signatures to prevent attackers from performing variant remote code execution in Apache Log4j2 (CVE-2021-44228)

Reference: https://www.fortiguard.com/updates/websecurity?version=0.00306

 

 

Carl_Windsor_FTNT
Staff
Staff
December 14, 2021

Note that the IPS signature changed to Default Block as of IPS DB 19.217

 

See our blog and advisory for more detail.

jsexton
New Member
December 14, 2021

We had a popup today on an end user machine indicated a detection and block for this. I can't find a reason for it, though. It's a workstation without Apache or Log4J installed. Does this plugin identify going to a vulnerable external website? My impression is that it only triggered on a machine if the machine itself was vulnerable.

Carl_Windsor_FTNT
Staff
Staff
December 14, 2021

Problem with this issue, the actual vulnerability can be behind the system being targetted (see the blog here).  FortiGate has no way of knowing if the server is vulnerable or of there is log4j somewhere in the path, just that the payload has been sent e.g. in a HTTP header.  This is the block you are seeing.

 

To know if you are potentially vulnerable, block outbound LDAP and look for triggers to the FW rule.

jsexton
New Member
December 16, 2021

Thank you. I'm still confused, though. EMS reports: "Apache.Log4j.Error.Log.Remote.Code.Execution has been blocked because it tried to receive network data., An unknown application" which is not very helpful. I'm seeing this on several PCs. None have apache or log4j installed. None are exposed directly to the internet, so I'm unclear how an attacker could even be reaching the machine. Is there anyway to get further detail about what is triggering the alert?