Sophisticated Attacks and Old Vulnerabilities: Organizations Using Fortinet at Risk
A breach allows attackers full control without authentication. Fortinet is warning of Zero-Day attacks targeting its firewalls and proxies, following a new security vulnerability (CVE-2024-55591) rated 9.6 out of 10. The flaw allows bypassing the authentication mechanism to gain Super-Admin access. An organization where FortiOS or FortiProxy versions have not been immediately updated is at high risk, as attackers can take over the system remotely and without the need for prior permissions. The U.S. cyber agency, CISA, announced that the patch must be implemented or exposed systems must be shut down by January 21st to protect federal agencies from attacks involving lateral movement.
Theft Details: Exposure of Configurations and Keys Across Various Countries
More than 15,000 IP addresses were leaked to BreachForums, endangering organizations. Concurrent with the alerts on the new vulnerability, configurations of over 15,000 Fortinet devices were leaked from a previous breach (CVE-2022-40684). Information including passwords, encryption keys, and firewall rules was published on the BreachForums forum, requiring organizations to evaluate not only updates for the current vulnerability but also password resets and audits regarding the old leak. Researchers emphasize that the data is organized into folders by country, and some passwords remained in plaintext format. Those who updated versions in time may be safer, but it is now also important to review update history and ensure the network was not breached in the past.
Threat Detection, Layered Defense, and Readiness
Updating security procedures and monitoring critical patches: Fortinet calls on its customers to check if their products contain previous vulnerabilities or are outdated, and if necessary, to implement security patches quickly or temporarily freeze the use of vulnerable versions. Additionally, researchers suggest that organizations update alert settings and limit external access to management interfaces. In the case of data exposed on BreachForums, it is recommended to change passwords and ensure a strict encryption policy—including multi-factor authentication (MFA) where possible.
Recommendations from IPV Security Information Security Experts:
1. Immediate Security Updates – Ensure updates to the latest versions of FortiOS and FortiProxy, and implement security patches as soon as possible.
2. Checking Old Exposure – Organizations appearing in previous leaks (CVE-2022-40684) are required to change passwords and review permission management policies.
3. Hardening Management Interfaces – Blocking access from the public network to management interfaces and enabling two-factor authentication wherever possible.
4. Monitoring Logs and Creating Alerts – Implement monitoring tools to detect suspicious and unauthorized activities, and consider using SIEM/SOAR for rapid response.
In summary, the recent security alerts surrounding Fortinet illustrate how both new and old vulnerabilities can increase risks to organizations. Alongside the potential impact of past data leaks, Fortinet device users are now facing a severe Zero-Day vulnerability that requires immediate attention. Taking steps such as regular updates, hardening configurations, and implementing advanced authentication can prevent future attacks and mitigate damage resulting from leaks and vulnerabilities.
For further information: https://www.databreachtoday.com/fortinet-users-see-active-zero-day-warnings-past-present-a-27320