Target Industry
Indiscriminate, opportunistic targeting.
Overview
The US Cybersecurity and Infrastructure Security Agency (CISA) has recently added a critical Fortinet vulnerability, CVE-2024-23113, to its Known Exploited Vulnerabilities (KEV) Catalogue. CVE-2024-23113 has been assigned a CVSS 3.1 score of 9.8, categorising it as a critical vulnerability. The vulnerability in the FortiOS fgfmd daemon allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. The issue is caused by an externally controlled format string vulnerability and affects older versions.
Impact
This vulnerability allows attackers to execute arbitrary code and commands via specially crafted packets. Having a CVSS v3.1 base score of 9.8, this vulnerability is classified as critical due to the low complexity required for exploitation.
Vulnerability Detection
Fortinet has released a security update addressing the security flaw in the respective product versions. As such, previous versions are vulnerable to potential exploits.
Exploitation
The vulnerability is actively being exploited in the wild and was added to the CISA KEV list.
Containment, Mitigations & Remediations
- FortiOS versions 7.4.0 to 7.4.2 should be updated to version 7.4.3 or higher
- FortiOS versions 7.2.0 to 7.2.2 should be updated to version 7.2.3 or higher
- FortiOS versions 7.0.0 to 7.0.2 should be updated to version 7.0.3 or higher
- All versions of FortiPAM 1.0 to 1.2 should be migrated to a fixed release
- FortiProxy versions 7.4.0 to 7.4.2 should be updated to version 7.4.3 or higher
- FortiProxy versions 7.2.0 to 7.2.8 should be updated to version 7.2.9 or higher
- FortiProxy versions 7.0.0 to 7.0.15 should be updated to version 7.0.16 or higher
- FortiWeb versions 7.4.0 to 7.4.2 should be updated to version 7.4.3 or higher
- FortiOS version 6.x is not affected
We strongly recommend that users of affected systems apply the update as soon as possible.
Where patching may not be possible for operational reasons, Fortinet has also provided a partial mitigation to the fgfmd vulnerability. For each interface it is recommended that the fgfm access is removed. Fortinet has provided the following example on the configuration update required:
config system interface
edit “portX”
set allowaccess ping https ssh fgfm
next
end
to :
config system interface
edit “portX”
set allowaccess ping https ssh
next
end
However, the company notes that this will prevent FortiGate discovery from FortiManager. A connection will still be possible from FortiGate.
Threat Landscape
Fortinet occupies a significant proportion of the networking-hardware market share. Given that threat actors generally utilise a combination of probability and asset value to determine which attack surfaces to develop exploits for, Fortinet networking hardware products have emerged as a prime target for threat actors. Due to the fact that Fortinet products have become an integral aspect of business operations, threat actors will continue to exploit the vulnerabilities of these product types in an attempt to exfiltrate sensitive data contained therein or impact associated business operations.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.
Further Information
https://www.cve.org/CVERecord?id=CVE-2024-23113
https://www.fortiguard.com/psirt/FG-IR-24-029
https://nvd.nist.gov/vuln/detail/CVE-2024-23113
https://cert.europa.eu/publications/security-advisories/2024-018/












