
THREAT LEVEL - HIGH
19-12-2024
New Critical FortiWLM Vulnerability
Threat Level Description
IthacaLabs has maintained the Threat Level (High) adding a new observation:An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.
Description
We have observed that a critical zero-day vulnerability affecting FortiWLM has been identified.
A remote unauthenticated attacker, by exploiting this issue, could execute arbitrary code and exfiltrate sensitive files containing configurations, IP addresses and credentials for managed devices.
This vulnerability, tracked as CVE-2023-34990, is a relative path traversal vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted web requests.
Fortinet created the “Fortinet Wireless Manager(FortiWLM)” to monitor, operate, and administer wireless networks on FortiGates that are managed by FortiManager.
The issue arises because the endpoint “/ems/cgi-bin/ezrf_lighttpd.cgi”, does not perform proper input validation on the “imagename” parameter. Due to this oversight, attackers can include directory traversal patterns (e.g., ../) in their requests, allowing them to access files beyond the intended directory structure.
Affected Products:
- FortiWLM versions 8.6.0 to 8.6.5
- FortiWLM versions 8.5.0 up to 8.5.4
Recommendation(s):
You should proceed immediately and apply the relevant security patches provided by the vendor.
You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.
References:
- https://www.fortiguard.com/psirt/FG-IR-23-144
- https://www.horizon3.ai/attack-research/disclosures/fortiwlm-the-almost-story-for-the-forti-forty
- https://vulnerability.circl.lu/cve/CVE-2023-34990
- https://nvd.nist.gov/vuln/detail/CVE-2023-34990
- IthacaLabs Incident Response and Threat Intelligence Services



