May 6, 2025
Trending News

Attackers exploit new vulnerability in FortiOS SSL VPN

  • February 9, 2024
  • 0

Cybercriminals are actively exploiting a new critical vulnerability in FortiOS SSL VPN. An update is available. Hackers are exploiting a major advantage of FortiOS SSL VPN. The vulnerability

Attackers exploit new vulnerability in FortiOS SSL VPN

Attackers exploit new vulnerability in FortiOS SSL VPN

Cybercriminals are actively exploiting a new critical vulnerability in FortiOS SSL VPN. An update is available.

Hackers are exploiting a major advantage of FortiOS SSL VPN. The vulnerability (CVE-2024-21762) receives a score of 9.6 and is therefore critical. It includes a outside the bordersWrite a security vulnerability in FortiOS that allows unauthorized attackers to execute proprietary malicious code, with potentially dramatic consequences.

Vulnerable versions

FortiOS 7.6 is not vulnerable to the bug. If you are already using the latest version of the software, you don’t have to worry about anything. The following releases are available and should therefore be patched as soon as possible:

software Vulnerable version Solution
FortiOS 7.4 7.4.0 to 7.4.2 Upgrade to 7.4.3 or later
FortiOS 7.2 7.2.0 to 7.2.6 Upgrade to 7.2.7 or later
FortiOS 7.0 7.0.0 to 7.0.13 Upgrade to 7.0.14 or later
FortiOS 6.4 6.4.0 to 6.4.14 Upgrade to 6.4.15 or later
FortiOS 6.2 6.2.0 to 6.2.15 Upgrade to 6.2.16 or later
FortiOS 6.0 6.0 all versions Migrate to a more recent version

If patching doesn’t work, you can temporarily close the leak by disabling SSL VPN on vulnerable FortiOS devices. While Fortinet says the flaw is being actively exploited, it does not provide any information about how or to what extent. It is also unclear who discovered the vulnerability.

Interesting goal

Fortinet is an interesting target for attackers because a vulnerability could allow access to the larger corporate network. This is interesting, for example, for ransomware attacks. Recently, it emerged that FortiSIEM is also vulnerable to hacker attacks due to critical flaws. Fortinet also offers updates for this.

Source: IT Daily

Leave a Reply

Your email address will not be published. Required fields are marked *