FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
alif
Staff
Staff
Article Id 327803

 

Description This article describes the forensic image to detect Coathanger.
Scope FortiOS, FortiGate, Vulnerability.
Solution

Fortinet is aware of the advisory released by Netherlands intelligence and security services. Although the Netherlands Military only released its advisory, this vulnerability was published in December 2022 (CVE-2022-42475).

 

PSIRT Heap-based buffer overflow in sslvpnd

 

There is an article which gives instructions on how to check the devices to see if they are affected:
Technical Tip: [Critical vulnerability] Protect against heap-based buffer overflow in sslvpnd

 

It is just a subset of device attacks Fortinet is already aware of and was caused by abuse of unpatched vulnerabilities. There is a blog post on the broader topic here:
PSIRT Blogs The Importance of Patching: An Analysis of the Exploitation of N-Day Vulnerabilities

 

There is also a blog post from January 2023 that gives a detailed analysis (it was made in cooperation with the Netherlands Military).
PSIRT Blogs Analysis of FG-IR-22-398 – FortiOS - heap-based buffer overflow in SSLVPNd

 

Fortinet does not provide forensic disk images. The reason mentioned in the Dutch advisory is that it has been collaborated with the PSIRT team on this vulnerability.

 

In case of any further queries, the PSIRT team can be contacted at PSIRT contact.

 

Contributors