A critical security vulnerability affecting over 87,000 FortiOS devices has been discovered, leaving them exposed to potential remote code execution (RCE) attacks.
The flaw, identified as CVE-2024-23113, impacts multiple versions of FortiOS, FortiProxy, FortiPAM, and FortiWeb products.
The vulnerability stems from a use of externally-controlled format string in the FortiOS fgfmd daemon, which allows unauthenticated remote attackers to execute arbitrary code or commands through specially crafted requests.
This critical flaw has been assigned a CVSS score of 9.8 out of 10, indicating its severe nature.
Analyse Any Suspicious Files With ANY.RUN: Intergarte With You Security Team -> Try for Free
According to Shadowserver scans, approximately 87,390 IP addresses associated with potentially vulnerable Fortinet devices have been identified. The United States leads with 14,000 affected devices, followed by Japan (5,100) and India (4,800).
The vulnerability impacts FortiOS versions 7.0 through 7.4.2, as well as various versions of FortiPAM, FortiProxy, and FortiWeb. Fortinet has released patches for the affected products and strongly recommends users upgrade to the latest secure versions.
As a temporary workaround, Fortinet advises removing fgfm access for each interface. However, this may prevent FortiGate discovery from FortiManager.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-23113 to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation in the wild.
This development has prompted CISA to order federal agencies to patch their FortiOS devices within three weeks, by October 30.
Given the widespread use of Fortinet products in enterprise and government networks, this vulnerability poses a significant risk to organizations worldwide. Security experts urge immediate action to mitigate the threat:
As threat actors continue to target known vulnerabilities, prompt action is crucial to protect critical infrastructure and sensitive data from potential compromise.
How to Choose an ultimate Managed SIEM solution for Your Security Team -> Download Free Guide(PDF)
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…