THREAT LEVEL - HIGH

17-01-2025

A New Critical Zero-Day Vulnerability in Fortinet FortiOS and FortiProxy Actively Exploited

Threat Level Description

IthacaLabs has maintained the Threat Level (High) adding a new observation:

An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.

Description

We have observed that a critical vulnerability impacting Fortinet FortiOS and FortiProxy has been identified.

An attacker, by exploiting this vulnerability, could gain super-admin privileges through crafted requests.

The vulnerability, tracked as CVE-2024-55591 is an authentication bypass in the Node.js WebSocket module.

Cybersecurity researchers have identified that attackers are targeting exposed FortiGate firewall management interfaces. Attackers used unauthorized administrative logins, created super admin accounts, modified configurations, and extracted credentials using the DCSync technique.

Fortinet has confirmed that this vulnerability has been actively exploited in the wild. Attackers have made unauthorized changes to firewall policies and created malicious user groups.

Affected Systems

FortiOS:

  1. Versions 7.0.0 – 7.0.19

  2. Versions 7.2.0 – 7.2.12

     

FortiProxy:

  1. Versions 7.0.0 – 7.0.16

Recommendation(s)

You should proceed to apply all security patches provided by the vendor immediately.

Furthermore, you should consider restricting access to the management interface to trusted internal IP addresses only, preventing unauthorized external access from the internet.

You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.

References:

 

SIGN UP

Get the latest Threat Alerts in your inbox.