home.social

#fortimanager — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fortimanager, aggregated by home.social.

fetched live
  1. A coordinated brute-force campaign has targeted Fortinet SSL VPNs, over 780 unique IPs launched credential attacks on August 3, followed by a change of target from FortiOS to FortiManager.

    Read: hackread.com/brute-force-campa

    #Cybersecurity #Fortinet #BruteForce #CyberAttack #FortiOS #FortiManager

  2. Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager CVE-2024-47575

    "The low complexity of these #vulnerabilities brings into question the overall quality of the #FortiManager codebase...
    As far as we can make out, Fortinet just patched a chunk of irrelevant (dead?) code and left the actual #vulnerability alone, wide open for attackers."
    labs.watchtowr.com/hop-skip-fo

  3. ...et ce n'est pas fini!

    watchTowr fait le "teasing" sur le bad site de leur prochaine publication en conseillant carrément au détenteurs de Foritmanager exposé: "S'il vous plaît, retirez le d'Internet *même s'il est entièrement corrigé"

    Le correctif pour la vulnérabilité « FortiJump » dans la plateforme de gestion FortiManager de Fortinet pourrait ainsi ne pas avoir complètement résolu le problème. Malgré une mise à jour récente, des preuves montrent que la vulnérabilité CVE-2024-47575 est encore exploitable, ce qui expose potentiellement 62 000 instances de FortiManager connectées à Internet selon Cyble threat intelligence.
    ⬇️
    "FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch
    The FortiJump vulnerability in Fortinet FortiManager may not have been completely fixed by last month's patch. Users are urged to apply mitigations."
    👇
    thecyberexpress.com/fortimanag

    #CyberVeille
    #CVE_2024_47575
    #Fortinet #FortiJump #Fortimanager

  4. 🚨CERT ALERT: FortiManager critical 0-day vulnerability exploited in the wild.

    It's been discussed off the record since the time of release earlier last week. 🤫

    The threat level of this advisory is thus considered very high (5/5, maximum severity level).📈🚨

    👉🤓Read Orange CyberDefense’s detailed World Watch Advisory to learn more: ow.ly/Wai430sHtfk

    #fortimanager
    #vulnerabilitymanagement #cybersecurity

  5. ❗️ #CERTWarnung ❗️
    In #FortiManager von Fortinet wurde eine Zero-Day #Schwachstelle geschlossen, die seit Juni ausgenutzt wird. Eine Kompromittierung ist zu prüfen. Kunden sollten unverzüglich ihre Geräte absichern. #PatchNow
    bsi.bund.de/SharedDocs/Cybersi

  6. fortiguard.com/psirt/FG-IR-24-

    „A missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.“

    Patch & establish micro-segmentation (only dedicated sources should be able to access FortiManager (and everything else); Use e.g. private-vlans & tighten your acls/firewall-policies)

    #infosec #fortinet #fortimanager

  7. The Reddit threads on this have been something. Advisory and CVE finally available for the #FortiManager 0day that's been knocking around social media, trust circles, and customer email inboxes for a week+ now. Since exploitation has evidently been ongoing for a while, patching alone may not be enough — Fortinet has a bunch of IOCs and recovery directions in their advisory, so check those out. Would also strongly recommend relying directly on the vendor advisory for affected/fixed versions, as we have seen these expand, sometimes significantly, for some prior Fortinet vulns.

    rapid7.com/blog/post/2024/10/2

    Advisory (assuming the PSIRT page stays up today!): fortiguard.com/psirt/FG-IR-24-

  8. @GossiTheDog Around 700 to 1100 FortiManagers are internet facing. That should be changed to 0. Only dedicated source ip addresses like hardened closely monitored jump servers should have access to FortiManagers/Firewall mgmt interfaces.

    shodan.io/search?query=fortine

    shodan.io/search?query=mapserv

    #infosec #fortinet #fortimanager

  9. Patch your FortiManager now. Limit access to it to only from dedicated jump-servers.

    #fortinet #fortimanager #infosec

  10. Happy Patch Tuesday from your friends at Fortinet. 13 security advisories, 15 vulnerabilities. No mention of exploitation in the wild:

    • FG-IR-23-087 CVE-2023-45590 (9.6 critical) [FortiClient Linux] Remote Code Execution due to dangerous nodejs configuration
    • FG-IR-23-345 CVE-2023-45588 and CVE-2024-31492 (8.2 high) FortiClientMac - Lack of configuration file validation
    • FG-IR-23-419 CVE-2023-47542 (6.7 medium) FortiManager - Code Injection via Jinja Template
    • FG-IR-23-288 CVE-2023-48785 (4.8 medium) FortiNAC-F - Lack of certificate validation
    • FG-IR-23-413 CVE-2023-48784 (6.7 medium) FortiOS - Format String in CLI command
    • FG-IR-23-224 CVE-2024-23662 (5.3 medium ) FortiOS - Web server ETag exposure
    • FG-IR-23-493 CVE-2023-41677 (7.5 high) FortiOS & FortiProxy - administrator cookie leakage
    • FG-IR-23-454 CVE-2024-23671 (8.1 high) FortiSandbox - Arbitrary file delete on endpoint
    • FG-IR-24-060 CVE-2024-31487 (5.9 medium) FortiSandbox - Arbitrary file read on endpoint
    • FG-IR-23-416 CVE-2023-47541 (6.7 medium) FortiSandbox - Arbitrary file write on CLI leading to arbitrary code execution
    • FG-IR-23-411 CVE-2023-47540 (6.7 medium) FortiSandbox - Command injection impacting CLI command
    • FG-IR-23-489 CVE-2024-21755 and CVE-2024-21756 (8.8 high) FortiSandbox - OS command injection on endpoint
    • FG-IR-24-009 CVE-2024-26014 (5.3 medium) SMTP Smuggling (analyst note: third party vulnerability)

    #PatchTuesday #Fortinet #FortiManager #vulnerability #FortiSandbox #FortiOS #FortiProxy

  11. Here are the CLI commands to check for the file artifacts on a #fortigate to determine if your system was affected by the vulnerability in CVE-2022-42475:
    fnsysctl ls /data/lib
    fnsysctl ls /data/var
    These were not documented in the PSIRT. You can run them directly on the fortigate, script them through a #fortimanager or through the cloud management console.
    #infosec #netsec #firewall #fortinet