watchTowr Finds New Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-23113 | Format String Vulnerability Enables Unauthenticated RCE in Fortinet FortiOS and FortiProxy CVE-2024-23113 is a use of externally-controlled format string (CWE-134) in multiple Fortinet products, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specially crafted packets to an affected device. The flaw carries a critical CVSS 3.1 score of 9.8 (network vector, no privileges or user interaction required, high impact on confidentiality, integrity, and availability). It affects FortiOS 7.0.0 through 7.0.13, 7.2.0 through 7.2.6, and 7.4.0 through 7.4.2; FortiProxy 7.0.0 through 7.0.14, 7.2.0 through 7.2.8, and 7.4.0 through 7.4.2; FortiPAM 1.0.0 through 1.0.3, 1.1.0 through 1.1.2, and 1.2.0; and FortiSwitchManager 7.0.0 through 7.0.3 and 7.2.0 through 7.2.3. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-10-09 and warns it is likely being exploited in the wild, though no public proof-of-concept is known. Scanning coverage reported in the trade press indicates roughly 87,000 or more internet-exposed Fortinet devices remained vulnerable and open to attack after disclosure. Do: Upgrade affected FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager deployments to a patched release per Fortinet's advisory, since the data does not specify fixed build numbers. Until patching is complete, restrict management interface access to trusted sources, minimize internet exposure of affected devices, and verify your version falls within the affected ranges above. Treat this as an actively exploited vulnerability per CISA's KEV listing (added 2024-10-09) and prioritize it accordingly. | 9.8 | 62% | KEV |
| large≈87,000+ internet-exposed Fortinet devices per public scans (FortiOS/FortiProxy deployments; total installed base larger, affected-version share unknown) | |
| CVE-2024-47575 | Unauthenticated RCE in Fortinet FortiManager and FortiManager Cloud CVE-2024-47575 is a missing-authentication flaw (CWE-306) in Fortinet FortiManager and FortiManager Cloud, rated critical at CVSS 9.8. An unauthenticated remote attacker can send specially crafted requests to the affected management interface and execute arbitrary code or commands, with no credentials, privileges, or user interaction required. Every supported FortiManager branch from 6.2 through 7.6 and four FortiManager Cloud branches are affected, meaning any organization using these products as the central management plane for FortiGate firewalls is exposed, and compromise of the appliance can provide a foothold across the entire managed firewall estate. The flaw was exploited as a zero-day in an active campaign before patches were available, was added to CISA KEV on 2024-10-23 (ransomware use not yet confirmed), and carries a 95.1% EPSS probability of exploitation within 30 days. Do: Upgrade FortiManager and FortiManager Cloud to the fixed releases listed in Fortinet advisory FG-IR-24-423 (FortiManager 7.6.1+, 7.4.5+, 7.2.8+, 7.0.13+, 6.4.15+, or 6.2.13+; Cloud 7.4.5+, 7.2.8+, 7.0.13+, or 6.4.8+), or apply the interim mitigations of restricting which IP addresses may connect to the fgfm service, disabling fgfm where it is not required, and applying the vendor's IPS signature. Hunt logs for signs of exploitation, such as unexpected fgfm requests, unknown IPs, or unexplained device registrations on the FortiManager. As a CISA KEV entry, federal agencies and other CISA-directed organizations must apply the mitigations or discontinue use of the product by the required deadline. | 9.8 | 95% | KEV PoC |
| moderate≈5,000 internet-exposed FortiManager/Cloud instances (order of thousands); total on-prem deployments likely higher |
Full article594 words · extracted from infosecurity-magazine.com · click to collapse
Attack surface management provider watchTowr claims to have found a new zero-day vulnerability in cybersecurity provider Fortinet’s products.
This flaw would allow a managed FortiGate device to elevate privileges and seize control of the FortiManager instance.
This new vulnerability is similar to a previous flaw discovered in October, CVE-2024-47575, also known as “FortiJump.” Researchers at watchTowr named it “FortiJump Higher.”
Background on FortiJump
FortiJump, or CVE-2024-47575, is a vulnerability in FortiManager, a Fortinet tool used by device administrators to maintain entire fleets of FortiGate appliances.
More specifically, FortiJump is the result of a missing authentication for a critical function (CWE-306) in the FortiManager fgfmd daemon that allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
It allows threat actors to use a compromised FortiManager device to execute arbitrary code or commands against other FortiManager devices.
This vulnerability, which carries a common vulnerability severity score (CVSS) of 9.8, is actively exploited in the wild, sometimes together with CVE-2024-23113, another vulnerability in Fortinet products discovered in February 2024.
— Matt Johansen (@mattjay) November 14, 2024🚨 Fortinet CVE-2024-23113 - actively exploited by state-sponsored hackers - is now being exploited by cybercriminals who have reverse-engineered it and are selling access to compromised devices
If you haven't patched, restrict port 541 to approved IPs or enforce cert auth. pic.twitter.com/8ay8TnFq1b
FortiJump has been analyzed by several security providers, including Google Cloud-owned Mandiant, Bishop Fox and Rapid 7.
Discovery of FortiJump Higher
In a new report published on November 15, watchTowr said it came across some new issues in FortiManager while trying to reproduce a FortiJump exploit in its lab.
Specifically, watchTowr claimed to have found a new vulnerability with a similar exploit technique that triggers FortiJump – FortiJump Higher – as well as two file overwrite vulnerabilities that could be leveraged to crash the system.
The company also claimed that the patch released by Fortinet, supposed to fix FortiJump, is not effective for all exploit methods.
“[Our findings] imply that Fortinet has simply patched the wrong code, in the wrong file, in an entirely different library,” the watchTowr researchers said in the report.
They claimed FortiJump Higher remains effective even in patched versions, enabling adversaries to escalate privileges from a managed FortiGate appliance to the central FortiManager appliance. They added that compromising any managed FortiGate appliance can be leveraged to gain control over the FortiManager itself – and, consequently, all other managed appliances.
“While we don’t have visibility into the inner workings of advanced persistent threat (APT) groups, in our opinion, it seems highly likely that successful APT groups are not entirely stupid and hold a high probability that if they found one vulnerability in this magical solution of spaghetti – they likely spotted others, which Fortinet have left untouched,” they added. “The low complexity of these vulnerabilities brings into question the overall quality of the FortiManager codebase.”
watchTowr said it contacted Fortinet about this new vulnerability. Nevertheless, it decided to publish its findings before any public response from the security company because its researchers believe that the similarities between FortiJump and FortiJump Higher mean that threat actors actively exploiting the former are likely also exploiting the latter.
Infosecurity has contacted Fortinet. A company spokesperson confirmed the new findings have “been sent on to Fortinet’s HQ, who are handling this request and will be in touch as soon as possible.”
This is a developing story and this article may be updated as new information becomes available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/watchtowr-new-vulnerability/