Target Industry

Indiscriminate, opportunistic targeting.

Overview

Fortinet has recently disclosed a critical application programming interface (API) vulnerability in FortiManager, identified as CVE-2024-47575, which has been actively exploited in the wild. This vulnerability has a critical severity with a CVSS v3.1 base score of 9.8 out of 10. The vulnerability, identified as a missing authentication for critical function in the FortiManager fgfmd daemon, could permit a remote, unauthenticated attacker to execute arbitrary code or commands by sending specially crafted requests.

Impact

An attacker can exploit this flaw remotely over the network without requiring any privileges or user interaction. Due to its low attack complexity, it is relatively easy for attackers to exploit. The potential impacts are severe and include unauthorised access to critical functions, execution of arbitrary code or commands on affected systems. The vulnerability has complete compromise of system confidentiality, integrity, and availability. There is also the potential for lateral movement within the network, data theft, manipulation, or destruction, and service disruptions or system takeover. Threat actors could take advantage of the vulnerability by using FortiManager and FortiGate devices under their control, equipped with valid certificates, to register on any accessible FortiManager server. After connecting their device, even if it were unauthorised, a threat actor could leverage the vulnerability to run API commands on the FortiManager and extract configuration data about the managed devices.

Vulnerability Detection

Fortinet has released a security update addressing the security flaw in the respective product versions. As such, previous versions are vulnerable to potential exploits.

For detailed information on the versions affected by this vulnerability and the corresponding patch solutions, please visit the vendor page at https://www.fortiguard.com/psirt/FG-IR-24-423.

Exploitation

This vulnerability is actively being exploited in the wild, highlighting the urgency for users to update their systems. There is no evidence that a public proof-of-concept exists. The vulnerability has been exploited since June 2024 in zero-day attacks on over 50 servers.

Containment, Mitigations & Remediations

We strongly recommend that users of the affected Fortinet systems apply the update as soon as possible.

If immediate patching is not feasible, Fortinet has provided several mitigation steps for those unable to immediately update their firmware:

  • Use the command ‘set fgfm-deny-unknown enable’ to prevent devices with unknown serial numbers from registering
  • Create a custom certificate for SSL tunnel authentication between FortiGate devices and FortiManager
  • Implement an allowed list of IP addresses for FortiGate devices that are permitted to connect
  • Limit access to FortiManager admin portal for only approved internal IP addresses
  • Only allow permitted FortiGate addresses to communicate with FortiManager
  • Deny unknown FortiGate devices from being associated with FortiManager.

Threat Landscape

Given the critical nature of this vulnerability and the active exploitation, it is crucial for organisations using FortiManager to remain vigilant and apply necessary security measures promptly.

Threat Group

Mandiant’s investigation revealed the emergence of a new threat group, UNC5820, which began exploiting this vulnerability as early as 27th June 2024. The report indicates that UNC5820 “gathered and extracted the configuration data of the FortiGate devices managed by the compromised FortiManager.”

Indicators of Compromise

IP Addresses:

  • 45[.]32.41.202
  • 104[.]238.141.143
  • 158[.]247.199.37
  • 45[.]32.63.2

Further Information

https://www.bleepingcomputer.com/news/security/fortinet-warns-of-new-critical-fortimanager-flaw-used-in-zero-day-attacks/

https://www.bleepingcomputer.com/news/security/mandiant-says-new-fortinet-fortimanager-flaw-has-been-exploited-since-june/

https://cyberplace.social/@Vidmo/113357373834486123

https://www.cve.org/CVERecord?id=CVE-2024-47575

https://www.fortiguard.com/psirt/FG-IR-24-423

https://cloud.google.com/blog/topics/threat-intelligence/fortimanager-zero-day-exploitation-cve-2024-47575

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content