High-severity FortiManager bug being exploited by hackers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-47575 | Unauthenticated RCE in Fortinet FortiManager and FortiManager Cloud CVE-2024-47575 is a missing-authentication flaw (CWE-306) in Fortinet FortiManager and FortiManager Cloud, rated critical at CVSS 9.8. An unauthenticated remote attacker can send specially crafted requests to the affected management interface and execute arbitrary code or commands, with no credentials, privileges, or user interaction required. Every supported FortiManager branch from 6.2 through 7.6 and four FortiManager Cloud branches are affected, meaning any organization using these products as the central management plane for FortiGate firewalls is exposed, and compromise of the appliance can provide a foothold across the entire managed firewall estate. The flaw was exploited as a zero-day in an active campaign before patches were available, was added to CISA KEV on 2024-10-23 (ransomware use not yet confirmed), and carries a 95.1% EPSS probability of exploitation within 30 days. Do: Upgrade FortiManager and FortiManager Cloud to the fixed releases listed in Fortinet advisory FG-IR-24-423 (FortiManager 7.6.1+, 7.4.5+, 7.2.8+, 7.0.13+, 6.4.15+, or 6.2.13+; Cloud 7.4.5+, 7.2.8+, 7.0.13+, or 6.4.8+), or apply the interim mitigations of restricting which IP addresses may connect to the fgfm service, disabling fgfm where it is not required, and applying the vendor's IPS signature. Hunt logs for signs of exploitation, such as unexpected fgfm requests, unknown IPs, or unexplained device registrations on the FortiManager. As a CISA KEV entry, federal agencies and other CISA-directed organizations must apply the mitigations or discontinue use of the product by the required deadline. | 9.8 | 95% | KEV PoC |
| moderate≈5,000 internet-exposed FortiManager/Cloud instances (order of thousands); total on-prem deployments likely higher |
Full article707 words · extracted from therecord.media · click to collapse
Updated Oct. 24 at 11:30am EST with additional details from Mandiant. The cybersecurity company Fortinet has publicly disclosed a vulnerability being exploited by hackers that affects a key tool allowing companies to manage multiple products in a single pane. Fortinet had been privately warning customers about the vulnerability — which affects FortiManager and is tagged as CVE-2024-47575 — since October 13 but began to face pressure to release details publicly after users began to speak out on Reddit and other social media sites with their concerns. The security giant released a public advisory about it on Wednesday, confirming exploitation reports and warning that several versions of FortiManager, as well as FortiManager Cloud, are affected. A patch has been released and the company has listed several workarounds users can deploy. “The identified actions of this attack in the wild have been to automate via a script the exfiltration of various files from the FortiManager which contained the IPs, credentials and configurations of the managed devices,” Fortinet explained. “At this stage, we have not received reports of any low-level system installations of malware or backdoors on these compromised FortiManager systems. To the best of our knowledge, there have been no indicators of modified databases, or connections and modifications to the managed devices.” The bug carries a critical severity score of 9.8 and allows hackers to steal troves of sensitive information that would facilitate further access. Cybersecurity firm Mandiant on Wednesday night said it worked with Fortinet to investigate more than 50 potentially compromised FortiManager devices across “various industries” throughout the month of October. “Mandiant observed a new threat cluster we now track as UNC5820 exploiting the FortiManager vulnerability as early as June 27, 2024. UNC5820 staged and exfiltrated the configuration data of the FortiGate devices managed by the exploited FortiManager,” Mandiant explained in an advisory. “This data contains detailed configuration information of the managed appliances as well as the users and their FortiOS256-hashed passwords. This data could be used by UNC5820 to further compromise the FortiManager, move laterally to the managed Fortinet devices, and ultimately target the enterprise environment.” After the initial exploitation attempt in June, they saw a second attempt on September 23. Google Cloud notified customers who had been affected. The company added that there is “no evidence that UNC5820 leveraged the obtained configuration data to move laterally and further compromise the environment.” Mandiant is unable to identify where the threat actor is located or what their motivation is. The advisory warns that any organization with FortiManager exposed to the internet should conduct a forensic investigation immediately. The Cybersecurity and Infrastructure Security Agency (CISA) confirmed the bug’s exploitation in an advisory on Wednesday, giving federal civilian agencies until November 13 to patch the issue. CISA said it is not clear whether ransomware gangs are exploiting the bug but cybersecurity expert Kevin Beaumont, who has been warning about it since October 13, said it is being used by nation-state attackers. Beaumont dubbed the bug ‘FortiJump’ and said on Tuesday that nearly 60,000 FortiManager instances are exposed on the internet, with more than 13,200 in the U.S. He noted that a threat actor exploiting the bug has been using another Fortinet vulnerability from February — CVE-2024–23113 — as an entry point before exploiting CVE-2024-47575 for wider access. CISA warned federal civilian agencies two weeks ago that the earlier bug was being exploited and gave them until October 30 to patch. “From the FortiManager, you can then manage the legit downstream FortiGate firewalls, view config files, take credentials and alter configurations,” Beaumont said in a blog. “Because MSPs — Managed Service Providers — often use FortiManager, you can use this to enter internal networks downstream.” Fortinet customers who spoke to Ars Technica and BleepingComputer expressed frustration with the company’s decision to wait weeks before publicly disclosing the bug, with several taking to Reddit to complain about being unaware of the issue.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/high-severity-fortimanager-bug-being-exploited