CISA warns of Fortinet bug likely being exploited in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21762 | Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted. Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority. | 9.8 | 84% | KEV ransomware |
| mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans) | |
| CVE-2024-23113 | Format String Vulnerability Enables Unauthenticated RCE in Fortinet FortiOS and FortiProxy CVE-2024-23113 is a use of externally-controlled format string (CWE-134) in multiple Fortinet products, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specially crafted packets to an affected device. The flaw carries a critical CVSS 3.1 score of 9.8 (network vector, no privileges or user interaction required, high impact on confidentiality, integrity, and availability). It affects FortiOS 7.0.0 through 7.0.13, 7.2.0 through 7.2.6, and 7.4.0 through 7.4.2; FortiProxy 7.0.0 through 7.0.14, 7.2.0 through 7.2.8, and 7.4.0 through 7.4.2; FortiPAM 1.0.0 through 1.0.3, 1.1.0 through 1.1.2, and 1.2.0; and FortiSwitchManager 7.0.0 through 7.0.3 and 7.2.0 through 7.2.3. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-10-09 and warns it is likely being exploited in the wild, though no public proof-of-concept is known. Scanning coverage reported in the trade press indicates roughly 87,000 or more internet-exposed Fortinet devices remained vulnerable and open to attack after disclosure. Do: Upgrade affected FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager deployments to a patched release per Fortinet's advisory, since the data does not specify fixed build numbers. Until patching is complete, restrict management interface access to trusted sources, minimize internet exposure of affected devices, and verify your version falls within the affected ranges above. Treat this as an actively exploited vulnerability per CISA's KEV listing (added 2024-10-09) and prioritize it accordingly. | 9.8 | 62% | KEV |
| large≈87,000+ internet-exposed Fortinet devices per public scans (FortiOS/FortiProxy deployments; total installed base larger, affected-version share unknown) | |
| CVE-2024-23313 | An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — |
Full article281 words · extracted from therecord.media · click to collapse
The top cybersecurity agency in the U.S. released two advisories on Friday about Fortinet vulnerabilities causing alarm among cybersecurity defenders. The Cybersecurity and Infrastructure Security Agency (CISA) released multiple warnings about CVE-2024-21762, a vulnerability affecting FortiOS SSL VPN that would allow an attacker to execute arbitrary code or commands. The vulnerability, which Fortinet disclosed on Thursday, was rated critical and carries a severity score of 9.6 out of 10. CISA’s level of alarm about the bug was apparent by the deadline they gave federal civilian agencies to patch the issue. They typically give agencies three weeks to patch almost all vulnerabilities, but for the second time ever they have ordered officials to install the patch within a week. Fortinet said it “is potentially being exploited in the wild,” while CISA said it was unsure whether it is being used by ransomware gangs. Fortinet urged customers to upgrade to the latest version. In another advisory, CISA warned of CVE-2024-23313, a bug that Fortinet does not believe is being actively exploited. CVE-2024-23113 had a higher severity rating at 9.8 out of 10. Fortinet devices are a popular target for nation-state hackers, particularly those associated with the Chinese government, because of their widespread use among governments. Last Tuesday, the Dutch Ministry of Defence said Chinese state-sponsored hackers broke into an internal computer network through a vulnerability in FortiGate devices. This week, CISA and the FBI warned that Chinese hackers that are part of the Volt Typhoon group have been seen exploiting vulnerabilities in networking appliances such as those from Fortinet. “They often use publicly available exploit code for known vulnerabilities but are also adept at discovering and exploiting zero-day vulnerabilities,” the advisory states.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-warns-fortinet-bug-likely-being-exploited