CyberzSOC

Publication detail
← Back to advisories & guidance

Fortinet Updates Guidance and Indicators of Compromise following FortiManager Vulnerability Exploitation ↗ source

October 30, 2024 CISA Alert

Summary

Fortinet has updated their security advisory addressing a critical FortiManager vulnerability (CVE-2024-47575) to include additional workarounds and indicators of compromise (IOCs). A remote, unauthenticated cyber threat actor could exploit this vulnerability to gain access to sensitive files or take control of an affected system. CISA previously added this vulnerability to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation, as confirmed by Fortinet. CISA strongly encourages users and administrators to apply the necessary updates, hunt for any malicious activity, assess potential risk from service providers, report positive findings to CISA, and review the following articles for additional information: Fortinet Advisory FG-IR-24-423 , CISA alert on the Fortinet FortiManager Missing Authentication Vulnerability , Google Threat Intelligence article Investigating FortiManager Zero-Day Exploitation (CVE-2024-47575) . This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-47575 9.8 Critical Fortinet FortiManager Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute a…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.