pwshub.com

Critical vulnerability in Fortinet’s FortiManager exploited in the wild

A critical vulnerability discovered in Fortinet Inc.’s FortiManager is being exploited in the wild, with users being advised to implement changes to protect against the threat.

The vulnerability – tracked as CVE-2024-47575 – affects Fortinet’s FortiManager platform versions prior to 7.6.1. Dubbed “FortiJump,” the vulnerability allows remote unauthenticated attackers to execute arbitrary code by exploiting weaknesses in the FortiGate-to-FortiManager protocol. The flaw allows attackers to register unauthorized devices, modify configuration files and potentially manage other networked devices.

Emphasizing its serious nature, the vulnerability has been assigned a Common Vulnerability Scoring System score of 9.8, which is critical on the CVSS scoring system. Fortinet has confirmed that the vulnerability is actively being exploited in the wild.

“The identified actions of this attack in the wild have been to automate via a script the exfiltration of various files from the FortiManager, which contained the IPs, credentials and configurations of the managed devices,” Fortinet said in an advisory.

While patches are available for some affected versions, administrators are being strongly advised to implement recommended mitigations if immediate patching is not feasible. The recommended patches include creating IP allow lists for authorized FortiGate devices and using custom certificates to reduce exposure.

FortiManager is a centralized management platform used to control Fortinet’s security devices, including firewalls, switches and access points. The service allows administrators to streamline security operations by providing tools for configuration management, policy updates and device monitoring across large networks. The platform also supports automation and orchestration to simplify complex network environments, enhancing security response and visibility.

Discussing the news, Victor Acin, head of Threat Intel at cybersecurity and risk management solutions provider Outpost24 AB, told SiliconANGLE via email that the “vulnerability in FortiManager is a clear example of how sophisticated zero-day attacks can target critical infrastructure.”

“This flaw, which allows unauthorized access to sensitive configuration files and credentials, underscores the importance of continuous monitoring and vigilance in cybersecurity,” Acin explains. “As attackers become more advanced, organizations must prioritize rapid detection and response to mitigate potential damage.”

Photo: Johannes Weber/Flickr

Source: siliconangle.com

Related stories
3 weeks ago - Observability and information technology management software company SolarWinds Worldwide LLC today announced the launch of the next generation of its observability platform that delivers full-stack visibility across all IT environments....
1 week ago - According to Business Insider and public filings, the S&P 500 has averaged a 10.5% return since 1957, which explains its popularity with investors. Even by that standard, it has been on a hot streak. It delivered a 24.2% return in 2023...
3 weeks ago - Cheap products are flowing into the American market from abroad, and the company is a major shipper.
1 month ago - Connected vehicles continue to increase in popularity with features such as remote access and start, but what if a hacker could access those same features to gain access to a car? A group of security researchers have revealed that it was...
2 days ago - A new white paper released today by Google LLC highlights its ongoing efforts to incorporate security across its products through a “Secure by Design” approach. The paper “An Overview of Google’s Commitment to Secure by Design” covers how...
Other stories
14 minutes ago - The Microsoft Corp.-owned professional networking platform LinkedIn has been ordered to pay €310 million ($334 million) by the European Union’s privacy regulator over targeted advertising practices, one the biggest fines to hit American...
14 minutes ago - Informatica LLC is looking to increase its relevance in generative artificial intelligence application development with the release today of several “blueprints” that outline the best way to create AI applications on different cloud...
14 minutes ago - The company had long promised “an even more affordable car” after the Model S and Model 3.
1 hour ago - Concentric Inc. said today it has closed on $45 million in a fresh round of funding led by Top Tier Capital Partners and HarbourVest Partners. The Series B round also saw the participation of CyberFuture and existing investors...
1 hour ago - Emerging markets are set for their worst monthly decline since January as investors price in higher odds of a Trump election win and higher tariffs.