FortiGate SSL-VPN credential disclosure via CVE-2018-13379 (2021)
What happened
On 8 September 2021 Fortinet's Product Security Incident Response Team published a notice that a malicious actor had disclosed SSL-VPN access credentials for 87,000 FortiGate devices. Fortinet stated that the credentials were obtained from systems that remained unpatched against CVE-2018-13379, its advisory FG-IR-18-384, at the time of the actor's scan, and that the vulnerability itself had been resolved in May 2019. CVE-2018-13379 is a path-traversal flaw in the FortiOS SSL-VPN web portal permitting an unauthenticated attacker to read system files, including the session file holding plaintext credentials. Fortinet's guidance was to disable all VPNs until remediation, upgrade to FortiOS 5.4.13, 5.6.14, 6.0.13 or 6.2.9 and above, treat all credentials as potentially compromised and perform an organisation-wide password reset, implement multi-factor authentication, and notify users. BleepingComputer reported the leaked set as roughly 500,000 credential pairs, a count of pairs rather than of devices.
A commodity network-appliance advisory, in this corpus because SPARTA cites it and because the reason it does is sound: ground segments are ordinary enterprise networks with a mission attached, and operator workstations, schedulers, front-end processors and modems sit behind the same remote-access appliances as everyone else's estate. The mission-specific parts of a ground system are not the part that gets compromised first. Two limits belong on the record. No source identifies a space-sector victim among the 87,000 and none is asserted, which is why IA-0007 is rejected rather than mapped. And the causal shape is unusual here: nothing was done to a spacecraft, a link or a mission system, and what is documented is the creation of an initial-access resource rather than its use. The two figures in circulation measure different things, 87,000 devices in the vendor advisory and about 500,000 credential pairs in the trade reporting; this record uses the vendor's.
Attack vector
Internet-wide scanning for FortiGate devices still unpatched against CVE-2018-13379, then exploitation of the FortiOS SSL-VPN web portal path traversal to read the session file containing plaintext credentials.
Operational impact
None reported against any named organisation. What is documented is the creation of a durable initial-access resource: valid SSL-VPN credentials for 87,000 devices, published.
Data compromised
SSL-VPN access credentials for 87,000 FortiGate devices, published by the actor. Reported elsewhere as approximately 500,000 credential pairs.
Disclosed
2021-09-08
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
The vulnerable component is the SSL-VPN web portal within FortiOS, the appliance's operating system, and the advisory's remediation is an operating-system version upgrade. Confidence is moderate rather than high because the defect sits in a bundled service rather than in the scheduling and memory-mediation primitives EX-0009.02's description centres on; EX-0009.03 is the more precise of the two and carries the high edge.
The actor mapped a commodity appliance's software version to a publicly known defect carrying an assigned CVE and exploited it at scale against systems where the available patch had not been applied. That is EX-0009.03's method, and Fortinet states it in its own advisory: the credentials came from systems that remained unpatched at the time of the actor's scan, more than two years after the fix shipped.
Credentials were taken from the affected devices and published by the actor. IMP-0006's framing is mission data gathered by a spacecraft, and these are enterprise access credentials, so the objects differ; the act it describes, data taken from a compromised system and removed, is described directly by the vendor and is not in doubt.
REC-0003.04 covers adversaries seeking any credential that would let them authenticate as a legitimate actor in space, ground or supporting cloud networks, and its description lists VPN and identity-provider tokens among the targets. A published corpus of valid FortiGate SSL-VPN credentials is that object exactly, and the technique's text names it. The evidence type is derived rather than direct: the technique's own description is what the edge is argued from, and no verbatim excerpt of the advisory was read against it.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
The credentials would enable this, and for some victims presumably did. No source names a ground system, a mission or an operator among the 87,000. Mapping it would be asserting a consequence nobody has reported.
The resource exists; no use of it is documented in these sources.
VPN passwords are not cryptographic key material in RD-0003.02's sense, which is about material conferring command or decryption authority. REC-0003.04 is the correct technique and is mapped.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Malicious Actor Discloses FortiGate SSL-VPN CredentialsVendor threat intelligence
Tier 1: The vendor's own product security incident response notice about its own product, published under its PSIRT process. Authoritative on the affected versions, the CVE, the device count and the remediation; an interested party on framing.
Tier 3: Security trade press reporting the forum posting. Tier 3: independent of the vendor, but its headline figure counts a different quantity from the vendor's and the discrepancy is not reconciled in either source.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.