Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

New Fortinet Zero-Day Exploited for Months Before Patch

A Fortinet zero-day tracked as CVE-2024-47575 and named FortiJump has been exploited since at least June 2024.

Fortinet vulnerability

A zero-day vulnerability patched recently by Fortinet has been exploited by threat actors since at least June 2024, according to Google Cloud’s Mandiant. 

Reports emerged roughly 10 days ago that Fortinet had started privately notifying customers about a FortiManager vulnerability that could be exploited by remote, unauthenticated attackers for arbitrary code execution.

FortiManager is a product that enables customers to centrally manage their Fortinet devices, particularly FortiGate firewalls.

Researcher Kevin Beaumont, who has been tracking reports of the vulnerability since the issue came to light, noted that Fortinet customers had initially only been provided with mitigations and the company later started releasing patches.

Fortinet publicly disclosed the vulnerability and announced its CVE identifier — CVE-2024-47575 — on Wednesday. The company also informed customers about the availability of patches for each impacted FortiManager version, as well as workarounds and recovery methods. 

Fortinet said the vulnerability has been exploited in the wild, but noted, “At this stage, we have not received reports of any low-level system installations of malware or backdoors on these compromised FortiManager systems. To the best of our knowledge, there have been no indicators of modified databases, or connections and modifications to the managed devices.” 

Advertisement. Scroll to continue reading.

Mandiant, which has helped Fortinet investigate the attacks, revealed in a blog post published late on Wednesday that to date it has seen over 50 potential victims of these zero-day attacks. These entities are from various countries and multiple industries.  

Mandiant said it currently lacks sufficient data to make an assessment regarding the threat actor’s location or motivation, and tracks the activity as a new threat cluster named UNC5820

The company has seen evidence suggesting that CVE-2024-47575 has been exploited since at least June 27, 2024. 

According to Mandiant’s researchers, the vulnerability allows threat actors to exfiltrate data that “could be used by the threat actor to further compromise the FortiManager, move laterally to the managed Fortinet devices, and ultimately target the enterprise environment.”

Beaumont, who has named the vulnerability FortiJump, believes that the flaw has been exploited by state-sponsored threat actors to conduct espionage through managed service providers (MSPs).

“From the FortiManager, you can then manage the legit downstream FortiGate firewalls, view config files, take credentials and alter configurations. Because MSPs […] often use FortiManager, you can use this to enter internal networks downstream,” Beaumont said. 

Beaumont, who runs a FortiManager honeypot to observe attack attempts, pointed out that there are tens of thousands of internet-exposed systems, and owners have been slow to patch known vulnerabilities, even ones exploited in the wild. 

Indicators of compromise (IoCs) for attacks exploiting CVE-2024-47575 have been made available by both Fortinet and Mandiant.

Related: Organizations Warned of Exploited Fortinet FortiOS Vulnerability

Related: Recent Fortinet FortiClient EMS Vulnerability Exploited in Attacks

Related: Fortinet Patches Code Execution Vulnerability in FortiOS

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.