• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
fortinet warns of critical fortios ssl vpn flaw likely under

Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation

You are here: Home / General Cyber Security News / Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation
February 9, 2024

Fortinet has disclosed a new critical security flaw in FortiOS SSL VPN that it claimed is possible currently being exploited in the wild.

The vulnerability, CVE-2024-21762 (CVSS score: 9.6), allows for the execution of arbitrary code and instructions.

“A out-of-bounds create vulnerability [CWE-787] in FortiOS could make it possible for a remote unauthenticated attacker to execute arbitrary code or command by using specifically crafted HTTP requests,” the enterprise stated in a bulletin released Thursday.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


It even further acknowledged that the issue is “probably being exploited in the wild,” with no supplying additional particulars about how it is really being weaponized and by whom.

Cybersecurity

The subsequent versions are impacted by the vulnerability. It is really really worth noting that FortiOS 7.6 is not affected.

  • FortiOS 7.4 (variations 7.4. via 7.4.2) – Up grade to 7.4.3 or over
  • FortiOS 7.2 (variations 7.2. via 7.2.6) – Up grade to 7.2.7 or above
  • FortiOS 7. (variations 7.. by 7..13) – Enhance to 7..14 or previously mentioned
  • FortiOS 6.4 (versions 6.4. by 6.4.14) – Improve to 6.4.15 or above
  • FortiOS 6.2 (versions 6.2. through 6.2.15) – Enhance to 6.2.16 or above
  • FortiOS 6. (variations 6. all versions) – Migrate to a fastened release

The growth comes as Fortinet issued patches for CVE-2024-23108 and CVE-2024-23109, impacting FortiSIEM supervisor, making it possible for a remote unauthenticated attacker to execute unauthorized commands by means of crafted API requests.

Before this week, the Netherlands authorities revealed a laptop network utilized by the armed forces was infiltrated by Chinese condition-sponsored actors by exploiting recognized flaws in Fortinet FortiGate equipment to provide a backdoor identified as COATHANGER.

The organization, in a report printed this week, divulged that N-day security vulnerabilities in its computer software, these kinds of as CVE-2022-42475 and CVE-2023-27997, are getting exploited by many action clusters to focus on governments, company suppliers, consultancies, manufacturing, and huge critical infrastructure businesses.

Previously, Chinese danger actors have been connected to the zero-working day exploitation of security flaws in Fortinet appliances to deliver a huge assortment of implants, such as BOLDMOVE, THINCRUST, and CASTLETAP.

It also follows an advisory from the U.S. government about a Chinese country-point out group dubbed Volt Typhoon, which has targeted critical infrastructure in the place for extensive-phrase undiscovered persistence by getting benefit of recognized and zero-day flaws in networking appliances these as all those from Fortinet, Ivanti Join Secure, NETGEAR, Citrix, and Cisco for preliminary entry.

Cybersecurity

China, which has denied the allegations, accused the U.S. of conducting its personal cyber-attacks.

If anything at all, the campaigns waged by China and Russia underscore the growing menace confronted by internet-dealing with edge units in new decades owing to the truth that this sort of technologies deficiency endpoint detection and response (EDR) aid, producing them ripe for abuse.

“These attacks display the use of previously settled N-working day vulnerabilities and subsequent [living-off-the-land] techniques, which are highly indicative of the behavior used by the cyber actor or group of actors acknowledged as Volt Typhoon, which has been using these methods to focus on critical infrastructure and probably other adjacent actors,” Fortinet stated.

Observed this write-up intriguing? Adhere to us on Twitter  and LinkedIn to read through far more special articles we put up.


Some elements of this short article are sourced from:
thehackernews.com

Previous Post: «warning: new ivanti auth bypass flaw affects connect secure and Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA Gateways
Next Post: Stealthy Zardoor Backdoor Targets Saudi Islamic Charity Organizations stealthy zardoor backdoor targets saudi islamic charity organizations»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.