A critical security vulnerability has been identified in Fortinet’s FortiOS and FortiProxy, potentially affecting over 133,000 devices worldwide.
The flaw, tracked as CVE-2024-21762, is an out-of-bounds write vulnerability that could allow a remote, unauthenticated attacker to execute arbitrary code or commands through specially crafted HTTP requests.
The vulnerability has been assigned a Common Vulnerability Scoring System (CVSS) score of 9.6, indicating its critical severity.
Fortinet has acknowledged that CVE-2024-21762 is “potentially being exploited in the wild,” urging users to apply the necessary updates to mitigate the risk.
Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities. :
AcuRisQ, that helps you to quantify risk accurately:
Fortiguard has identified an out-of-bounds write vulnerability [CWE-787] in FortiOS and FortiProxy.
A remote attacker can exploit this vulnerability without authentication, using specially crafted HTTP requests.
As a result, the attacker can execute arbitrary code or commands on the vulnerable device.
According to a recent tweet from ShadowServer, Fortinet is still vulnerable to attacks, with over 133,000 instances at risk.
This means that bad actors could exploit a potentially large attack surface.
The affected versions of FortiOS and FortiProxy, along with the recommended solutions, are as follows:
Users can follow the recommended upgrade path using Fortinet’s upgrade tool.
As a temporary measure, Fortinet advises disabling the SSL VPN feature, noting that simply disabling web mode is not a valid workaround.
The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that CVE-2024-21762 has been exploited by adding it to its Known Exploited Vulnerabilities Catalog.
The vulnerability has been exploited by attackers actively seeking to compromise devices that have not yet been patched.
Most potential targets are in the United States, India, Brazil, and Canada.
The urgency to patch the vulnerability is underscored by the high CVSS score and the ease of exploitation, which could grant attackers access to sensitive information.
Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…