← Intelligence Center
Intelligence Center
Fortinet Releases Advisory on New Post-Exploitation Technique for Known Vulnerabilities
CVEs
None identified.
Products
- •FortiOS
- •FortiGate
Executive Summary
Fortinet is aware of a threat actor creating a malicious file from previously exploited Fortinet RCE vulnerabilities within FortiOS and FortiGate products. This malicious file could enable read-only access to files on the devices' file system, which may include configurations.
Municipal Impact
Municipalities running FortiGate/FortiOS should upgrade to the indicated fixed versions and review device configurations, as exposed firewalls and SSL-VPNs are common targets.
SMB Impact
SMBs using FortiGate should upgrade to the fixed FortiOS versions, reset potentially exposed credentials, and consider disabling SSL-VPN until patched.
Recommended Actions
- Upgrade to FortiOS versions 7.6.2, 7.4.7, 7.2.11, 7.0.17, or 6.4.16 to remove the malicious file and prevent re-compromise.
- Review the configuration of all in-scope devices.
- Reset potentially exposed credentials.
- As a work-around mitigation until the patch is applied, consider disabling SSL-VPN functionality, as exploitation requires SSL-VPN to be enabled.
Grey Matter Analysis
Analysis pending review.
References
- https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fwww.fortinet.com%2fblog%2fpsirt-blogs%2fanalysis-of-threat-actor-activity&c=E,1,FCekCxWXlg-Vkgbo01at1wfotrtzvl7H2kYn_OWqO0TjKdUB1gv0JvBDM3urFitd1NTbDLLqoWmUT-SYrk4wBCna7v07zAVd6em6Ynsp1PQEj-65&typo=1
- https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fcommunity.fortinet.com%2ft5%2fFortiGate%2fTechnical-Tip-Recommended-steps-to-execute-in-case-of-a%2fta-p%2f230694&c=E,1,J8TpRFnUrlOfGNf4B2RgWu4Rl_xRiV1fLaug5Vnr19MLro-LdyvSBtlroDXI9zItpR4YqYIcDNYwsNQtNtsirffVvrFCj5q0LXBHmPIpjbirZNdm&typo=1
Tags
Related Intelligence
Get Help
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter