Target Industry

Indiscriminate, opportunistic targeting.

Overview

The US Cybersecurity and Infrastructure Security Agency (CISA) has recently added a critical Fortinet vulnerability, CVE-2024-23113, to its Known Exploited Vulnerabilities (KEV) Catalogue. CVE-2024-23113 has been assigned a CVSS 3.1 score of 9.8, categorising it as a critical vulnerability. The vulnerability in the FortiOS fgfmd daemon allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. The issue is caused by an externally controlled format string vulnerability and affects older versions.

Impact

This vulnerability allows attackers to execute arbitrary code and commands via specially crafted packets. Having a CVSS v3.1 base score of 9.8, this vulnerability is classified as critical due to the low complexity required for exploitation.

Vulnerability Detection

Fortinet has released a security update addressing the security flaw in the respective product versions. As such, previous versions are vulnerable to potential exploits.

Exploitation

The vulnerability is actively being exploited in the wild and was added to the CISA KEV list.

Containment, Mitigations & Remediations

  • FortiOS versions 7.4.0 to 7.4.2 should be updated to version 7.4.3 or higher
  • FortiOS versions 7.2.0 to 7.2.2 should be updated to version 7.2.3 or higher
  • FortiOS versions 7.0.0 to 7.0.2 should be updated to version 7.0.3 or higher
  • All versions of FortiPAM 1.0 to 1.2 should be migrated to a fixed release
  • FortiProxy versions 7.4.0 to 7.4.2 should be updated to version 7.4.3 or higher
  • FortiProxy versions 7.2.0 to 7.2.8 should be updated to version 7.2.9 or higher
  • FortiProxy versions 7.0.0 to 7.0.15 should be updated to version 7.0.16 or higher
  • FortiWeb versions 7.4.0 to 7.4.2 should be updated to version 7.4.3 or higher
  • FortiOS version 6.x is not affected

We strongly recommend that users of affected systems apply the update as soon as possible.

Where patching may not be possible for operational reasons, Fortinet has also provided a partial mitigation to the fgfmd vulnerability. For each interface it is recommended that the fgfm access is removed. Fortinet has provided the following example on the configuration update required:

config system interface

edit “portX”

set allowaccess ping https ssh fgfm

next

end

to :

config system interface

edit “portX”

set allowaccess ping https ssh

next

end

However, the company notes that this will prevent FortiGate discovery from FortiManager. A connection will still be possible from FortiGate.

Threat Landscape

Fortinet occupies a significant proportion of the networking-hardware market share. Given that threat actors generally utilise a combination of probability and asset value to determine which attack surfaces to develop exploits for, Fortinet networking hardware products have emerged as a prime target for threat actors. Due to the fact that Fortinet products have become an integral aspect of business operations, threat actors will continue to exploit the vulnerabilities of these product types in an attempt to exfiltrate sensitive data contained therein or impact associated business operations.

Threat Group

No attribution to specific threat actors or groups has been identified at the time of writing.

Further Information

https://www.cve.org/CVERecord?id=CVE-2024-23113

https://www.fortiguard.com/psirt/FG-IR-24-029

https://nvd.nist.gov/vuln/detail/CVE-2024-23113

https://cert.europa.eu/publications/security-advisories/2024-018/

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content