#fortijump — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #fortijump, aggregated by home.social.
-
...et ce n'est pas fini!
watchTowr fait le "teasing" sur le bad site de leur prochaine publication en conseillant carrément au détenteurs de Foritmanager exposé: "S'il vous plaît, retirez le d'Internet *même s'il est entièrement corrigé"
Le correctif pour la vulnérabilité « FortiJump » dans la plateforme de gestion FortiManager de Fortinet pourrait ainsi ne pas avoir complètement résolu le problème. Malgré une mise à jour récente, des preuves montrent que la vulnérabilité CVE-2024-47575 est encore exploitable, ce qui expose potentiellement 62 000 instances de FortiManager connectées à Internet selon Cyble threat intelligence.
⬇️
"FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch
The FortiJump vulnerability in Fortinet FortiManager may not have been completely fixed by last month's patch. Users are urged to apply mitigations."
👇
https://thecyberexpress.com/fortimanager-vulnerable-fortijump-patch/#CyberVeille
#CVE_2024_47575
#Fortinet #FortiJump #Fortimanager -
FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch https://thecyberexpress.com/fortimanager-vulnerable-fortijump-patch/ #vulnerabilitiesinFortinet #TheCyberExpressNews #ThreatIntelligence #TheCyberExpress #Vulnerabilities #FirewallDaily #cybersecurity #Vulnerability #FortiManager #Cyberattack #CyberNews #FortiJump #Fortinet
-
-
Don’t worry everybody, #FortiJump is back for Christmas… this time set in space! The patch didn’t fix the variants.
-
I think this got lost in the mix - the #FortiJump threat actress wasn’t just exploiting FortiManager.
Both FortiGate (the firewall product) and FortiManager (the central manager product) use FGFM on port 541.
The threat actress had different exploits for both products - the February FortiGate CVE and the new FortiManager CVE.
One recommended mitigation in FortiManager is you lock FGFM to allowed IPs of your FortiGates. If you pop the FortiGate first you can reach the FortiManager by design.
-
Fortinet Advisory for CVE-2024-47575 in FortiManager (RCE via fgfmsd daemon):
https://www.fortiguard.com/psirt/FG-IR-24-423Mandiant has details:
https://cloud.google.com/blog/topics/threat-intelligence/fortimanager-zero-day-exploitation-cve-2024-47575 -
Ah, ein Fortinet Zero Day. Glücklicherweise liefern die Leute auch ihren eigenen Soundtrack mit #fortijump
*düdü düd dü*
-
Germany’s BSI advisory about #FortiJump contains a fifth IP address, more to come. https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-282848-10Ub2.pdf?__blob=publicationFile&v=3
-
#FortiJump has been added to CISA KEV list. https://mastodon.social/@cisakevtracker/113358041133854343
-
FortiNet have now gone public about FortiJump, aka CVE-2024-47575 https://fortiguard.fortinet.com/psirt/FG-IR-24-423
Not in the advisory but exploitation stems to at least September, and it's being used to enter downstream networks.