ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

48,000+ internet-facing Fortinet firewalls still open to attack

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-55591

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-55591
Unauthenticated Super-Admin Bypass in Fortinet FortiOS and FortiProxy

CVE-2024-55591 is an authentication bypass (CWE-288) in the Node.js websocket module of Fortinet FortiOS and FortiProxy that lets a remote, unauthenticated attacker gain super-admin privileges via crafted websocket requests. It affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and is trivially triggerable from the network with no user interaction given network access to the management/websocket interface. Successful exploitation gives full super-admin control of the appliance, which attackers can use to pivot, create persistent access, and deploy ransomware. Any organization running the affected FortiOS or FortiProxy versions, especially with admin interfaces reachable from the internet, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, and multiple ransomware crews (reported as Gunra, SuperBlack, and Mora_001) are actively exploiting it.

Do: Upgrade all affected systems beyond the vulnerable ranges — FortiOS later than 7.0.16 and FortiProxy later than 7.0.19 / 7.2.12 — following Fortinet's advisory, or apply the vendor's mitigations where upgrades are not possible (per CISA KEV instructions). Restrict access to the admin/websocket interface from the internet, and hunt for unauthorized super-admin accounts and suspicious websocket connections, since ransomware operators are actively exploiting this flaw. Verify device versions and audit logs for signs of compromise before and after patching.

9.898% KEV ransomware
  • Fortinet FortiOS 7.0.0 through 7.0.16
  • Fortinet FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12
large≈48,000+ internet-exposed Fortinet devices per public scans, out of an installed base in the hundreds of thousands
Full article414 words · extracted from helpnetsecurity.com · click to collapse

Despite last week’s confirmation of and warnings about long-standing exploitation of CVE-2024-55591, a critical vulnerability affecting Fortinet Fortigate firewalls, too many vulnerable devices are still accessible from the Internet and open to attack: over 48,000, according to data from the Shadowserver Foundation.

Fortinet cve-2024-55591 attack

CVE-2024-55591 exploitation

On January 10, Artic Wolf Labs researchers outlined an attack campaign targeting FortiGate firewalls with management interfaces exposed on the public internet by exploiting a zero-day vulnerability.

It involved attackers scanning for vulnerable devices, exploiting the zero-day, logging into the management interface as admin, changing the device configuration, creating new or hijacking existing accounts, creating new SSL VPN portals, establishing SSL VPN tunnels with the affected devices, and extracting credentials for lateral movement.

Fortinet publicly confirmed its existence and use a few days later, when it also revealed the vulnerability’s CVE number, the availability of patches and workarounds, and indicators of compromise associated with the campaign.

The company also said it had been “proactively communicating with customers to provide guidance regarding CVE-2024-55591” and intimated that they’ve been confidentially sharing early guidance with some customers before the publication of the advisory.

On the same day (January 14), the US Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog.

What’s the latest?

According to Arctic Wolf, the campaign unfolded between November 16, 2024 and December 27, 2024.

On Friday, risk advisory firm Kroll stated that they’ve observed connections to FortiGate appliances from actor-controlled infrastructure that match reconnaissance activity starting on November 1, 2024.

“It is possible that this activity started earlier, but without access to the devices this is not possible to confirm,” said Associate Managing Director George Glass. “Kroll assesses that the campaign is opportunistic and is not confined to any industry or geography.”

The attackers’ ultimate goal is still unknown.

Organizations running FortiGate firewalls and FortiProxy web gateways should be implementing the provided security updates, removing management interfaces from the internet or limiting access to them to trusted internal users, checking for indicators for compromise and, if found, engaging in furter incident response actions.

Unfortunately, as Shadowserver data shows, many have yet to take the first two steps: On January 17, the organization detected approximately 52,000 vulnerable internet-facing FortiGate devices – five days later, that number has fallen to around 48,000.

The majority of these devices are located in Asia and North America.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/01/22/48000-internet-facing-fortinet-firewalls-still-open-to-attack/