Fortinet warns of active campaign exploiting bug in FortiManager products
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-47575 | Unauthenticated RCE in Fortinet FortiManager and FortiManager Cloud CVE-2024-47575 is a missing-authentication flaw (CWE-306) in Fortinet FortiManager and FortiManager Cloud, rated critical at CVSS 9.8. An unauthenticated remote attacker can send specially crafted requests to the affected management interface and execute arbitrary code or commands, with no credentials, privileges, or user interaction required. Every supported FortiManager branch from 6.2 through 7.6 and four FortiManager Cloud branches are affected, meaning any organization using these products as the central management plane for FortiGate firewalls is exposed, and compromise of the appliance can provide a foothold across the entire managed firewall estate. The flaw was exploited as a zero-day in an active campaign before patches were available, was added to CISA KEV on 2024-10-23 (ransomware use not yet confirmed), and carries a 95.1% EPSS probability of exploitation within 30 days. Do: Upgrade FortiManager and FortiManager Cloud to the fixed releases listed in Fortinet advisory FG-IR-24-423 (FortiManager 7.6.1+, 7.4.5+, 7.2.8+, 7.0.13+, 6.4.15+, or 6.2.13+; Cloud 7.4.5+, 7.2.8+, 7.0.13+, or 6.4.8+), or apply the interim mitigations of restricting which IP addresses may connect to the fgfm service, disabling fgfm where it is not required, and applying the vendor's IPS signature. Hunt logs for signs of exploitation, such as unexpected fgfm requests, unknown IPs, or unexplained device registrations on the FortiManager. As a CISA KEV entry, federal agencies and other CISA-directed organizations must apply the mitigations or discontinue use of the product by the required deadline. | 9.8 | 95% | KEV PoC |
| moderate≈5,000 internet-exposed FortiManager/Cloud instances (order of thousands); total on-prem deployments likely higher |
Full article866 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
At least 50 organizations have been hit by the campaign, Fortinet and Mandiant say, and federal agencies are on the hook to patch.
Listen to this article
0:00
Learn more.
Fortinet and Mandiant are sounding the alarms about an active campaign exploiting a critical bug in FortiManager products that allows a remote hacker to manage associated devices.
Mandiant and Fortinet investigated more than 50 organizations this month that were hit by the campaign, but found indications that it started as early as June 27. The Google-owned cybersecurity firm further warned in the new report that it lacks “sufficient data to assess actor motivation or location” and is currently tracking the cluster of activity as UNC5820.
The bug, CVE-2024-47575, resulted from a missing authentication and is given an estimated CVEE score of 9.8 by Fortinet.
Fortinet said in an alert Wednesday that it has found no indications of low-level system installations of malware and “there have been no indicators of modified databases, or connections and modifications to the managed devices.”
The vendor further stressed that organizations with impacted versions of FortiManager, FortiManager Cloud, some older FortiAnalyzer models with the FortiManager feature enabled, “and at least one interface with fgfm service enabled” should all patch or mitigate the bug and change credentials.
“We urge customers to follow the guidance provided to implement the workarounds and fixes and to continue tracking our advisory page for updates,” Fortinet said in a statement to CyberScoop. “We continue to coordinate with the appropriate international government agencies and industry threat organizations as part of our ongoing response.”
The Cybersecurity and Infrastructure Security Agency added the bug to the known exploited vulnerability catalog Wednesday. The move also starts the clock for federal civilian agencies, which are mandated to fix “critical risk” bugs within 15 days.
Mandiant said UNC5820 exfiltrated configuration data of multiple FortiGate devices managed by the exploited software, as well as users and associated passwords. However, the firm said there is no data that shows the hackers moving laterally through networks or using the exfiltrated data.
“This data could be used by UNC5820 to further compromise the FortiManager, move laterally to the managed Fortinet devices, and ultimately target the enterprise environment,” Mandiant said.
If exploited, Fortinet said the bug could allow a “remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.”
Caitlin Condon, director of vulnerability intelligence at Rapid7, told CyberScoop that the network security company is working with several potentially affected organizations but had no additional confirmations of the campaign yet. But Condon cautioned that it’s still early in the disclosure process, meaning more organizations will likely be making public disclosures soon.
Condon also noted in a Rapid7 report that some customers received “communications from service providers indicating the vulnerability may have been exploited in their environments.”
However, the disclosure process has been far from perfect. As Condon noted, private industry discussions around the potential exploit as well as some Reddit posts predicted the release of the bug. Some concerns were raised publicly as early as Oct. 13, more than a week before the release, and others expressed frustration about the disclosure process.
In a statement, Fortinet said the company “promptly communicated critical information and resources to customers. This is in line with our processes and best practices for responsible disclosure to enable customers to strengthen their security posture prior to an advisory being publicly released to a broader audience, including threat actors.”
In a blog post published Tuesday, security researcher Kevin Beaumont detailed how some customers were privately notified about the bug ahead of time. Beaumont further alleged that state-sponsored activity may be behind the campaign, dubbing the vulnerability “FortiJump.”
Beaumont said there were just under 60,000 vulnerable internet-facing FortiManager devices exposed as of Wednesday, with more than 13,000 found in the United States. China was a distant second with over 5,800 devices exposed.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/fortinet-fortimanager-mandiant-unc5820-alert/