Fortinet warns a critical vulnerability in its systems could let attackers breach company networks

Best free Linux firewalls
Image credit: Pixabay (Image credit: Pixabay)

  • Fortinet releases advisory urging users to apply available patch
  • Security researchers warn the bug is being exploited en-masse
  • CISA added the flaw to its KEV catalog

A zero-day vulnerability in firewalls built by Fortinet is being exploited en-masse to breach corporate networks and possibly deploy ransomware, the company has confirmed, with the findings backed up by a number of cybersecurity researchers.

The company recently published a security advisory, detailing a critical-severity vulnerability in the FortiGate firewalls. Tracked as CVE-2024-55591, this authentication bypass was given a severity score of 9.8, and said it affects FortiOS version 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19, and 7.2.0 through 7.2.12.

Malicious actors can abuse the bug to gain super-admin privileges, it was said.

Massive exploitation

In the advisory, Fortinet said the bug was “being exploited in the wild”, and used the opportunity to release a patch.

However, cybersecurity researcher from Arctic Wolf said the bug was already being massively exploited while it was a zero-day (before the patch).

Speaking to TechCrunch, ArcticWolf’s lead threat intelligence researcher Stefan Hostetler said that the company saw a cluster of intrusions that affected Fortinet devices “in the tens”, but added that it likely “only represents a limited sample compared to the total actual number” of affected endpoints. Unfortunately, no one was able to confirm even an estimated number of victims.

The researchers also could not attribute the attack to any particular threat actor. However, researcher Kevin Beaumont suggested that at least one of the threat actors is a ransomware operator. “They have a copy of an exploit and are using it for initial access and handing off for lateral movement,” he commented.

Yesterday, the US Cybersecurity and Infrastructure Security Agency (CISA) added four new vulnerabilities to its catalog of exploited flaws, including this FortiGate bug, meaning federal agencies have until February 4, 2025 to apply the patch or stop using FortiGate entirely.

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Digital image of a lock.
Fortinet flags some worrying security bugs coming back from the dead
A VPN runs on a mobile phone placed on a laptop keyboard
SonicWall firewalls hit by worrying cyberattack
The best free firewall
Palo Alto Networks PAN-OS sees authentication bypass under attack from hackers
The best free firewall
Palo Alto warns another major firewall hack has been detected
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
Representational image depecting cybersecurity protection
Hackers are breaking SonicWall products to target business networks
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over