GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Fortinet SSL VPN pre-auth RCE, exploitation in wild. Patch now. CVE-2024-21762

https://fortiguard.fortinet.com/psirt/FG-IR-24-015

I understand this is very easy to exploit, and applies to unsupported versions too.

interpipes,
@interpipes@thx.gg avatar

@GossiTheDog fortunately the only forti box we manage has ssl vpn off because it’s sitting on 7.4.2 and telling me there’s nothing newer.

interpipes,
@interpipes@thx.gg avatar

@GossiTheDog also this is great (from the 7.4.3 release notes)

GossiTheDog,
@GossiTheDog@cyberplace.social avatar
interpipes,
@interpipes@thx.gg avatar

@GossiTheDog FYI seems Fortigate still isn't (as of a couple of hours ago) offering 7.4.3 to people going into their fortinet device and checking for updates as they usually might, and so people might think they are up to date when they are not.... you have to pull the image from fortinet's site and upload it manually to upgrade atm :\

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

If I have to name this one it’s gonna have a toothbrush pun in it, FYI.

da_667,

@GossiTheDog dental appointment

video/mp4

gsuberland,
@gsuberland@chaos.social avatar

@da_667 @GossiTheDog lisa needs braces

barubary,
GossiTheDog,
@GossiTheDog@cyberplace.social avatar

A @shodan search for FortiOS boxes:

product:"Fortinet FortiGate"

Add org:YourOrg or ssl:YourOrg to find yours.

Obviously validate it's got VPN enabled by visiting the page.

There's a LOT of them - 6 figures, one of the biggest SMB appliances.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ngwrru68w68
  • DreamBathrooms
  • khanakhh
  • magazineikmin
  • InstantRegret
  • ethstaker
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • osvaldo12
  • everett
  • kavyap
  • Durango
  • megavids
  • cubers
  • tester
  • GTA5RPClips
  • modclub
  • mdbf
  • cisconetworking
  • tacticalgear
  • Leos
  • normalnudes
  • anitta
  • provamag3
  • JUstTest
  • lostlight
  • All magazines