Skip to main content
  • Critical Vulnerability In FortiOS And FortiProxy (CVE-2024-55591)

    CVSSv3 Score: Base 9.8 Critical

    BACKGROUND 

    Fortinet has identified a severe vulnerability in FortiOS and FortiProxy that allows unauthenticated 
    remote attackers to bypass authentication mechanisms and gain “super-admin” privileges.   
    Threat actors have been observed performing malicious post-exploitation activities, including the 
    creation of random administrative and local user accounts, modification of system configurations 
    (e.g., firewall policies), and the use of SSL VPN for unauthorized access to internal network. 

    IMPACT 

    • Attackers can create new administrative and local user accounts with random usernames, resulting in unauthorized access.
    • Attackers can access the SSL VPN with newly created local user accounts to establish a connection to the internal network.
    • Attackers can gain control of the affected system and perform administrative tasks such as: 
      o Adding users to existing or new SSL VPN user groups 
      o Modifying configurations, including SSL VPN settings 
      o Adding or changing firewall policies 
      o Altering or removing system configurations 
      o Deploying malicious payloads

    AFFECTED PRODUCTS

     ProductAffected Versions
    1FortiOS7.0.0 through 7.0.16
    2FortiProxy7.0.0 through 7.0.19
    3FortiProxy7.2.0 through 7.2.12

    RECOMMENDATIONS

    • Upgrade the affected versions to the fixed versions as soon as possible.
    • If immediate updates are not possible, implement the following workarounds:
      • Disable HTTP/HTTPS administrative interface or limit IP Addresses that can reach the administrative interface via local-in policies.
      • Remove the firewall’s web-based management interface from the public internet.
      • Ensure all connections to the device are monitored, and that audit logging for the device is enabled.
      • If required for operations, use ACLs to limit what IP addresses can access the port. This can be done directly on the device via the "my_allowed_addresses" configuration setting. 

    Note: Detailed recommended steps to follow can be found in Fortinet’s website at https://fortiguard.fortinet.com/psirt/FG-IR-24-535

    REFERENCES

    https://fortiguard.fortinet.com/psirt/FG-IR-24-535

    https://nvd.nist.gov/vuln/detail/CVE-2024-55591

    https://www.linkedin.com/pulse/fortinet-patches-zero-day-vulnerability-fortios-eotxe/

    https://www.bleepingcomputer.com/news/security/fortinet-warns-of-auth-bypass-zero day-exploited-to-hijack-firewalls/

    https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2024-55591 fortinet-fortios-fortiproxy-zero-day/

     

  • Address Bar Spoofing on Mozilla Firefox (CVE-2025-0244)

    CVSS SCORE: 5.3 Medium

    BACKGROUND 

    A security vulnerability has been identified in Mozilla Firefox that poses a serious threat to users on Android devices.  

    The vulnerability is classified as concerning because it involves a clickjacking issue, where an attacker can manipulate the user interface to spoof the address bar when redirecting to an invalid protocol scheme.  

    This issue could potentially mislead users into believing they are interacting with a legitimate site, creating an opportunity for phishing attacks.


    IMPACT

    • An attacker may spoof the address bar.
    • This could potentially lead to phishing attacks or other forms of social engineering. 
    • It may result in the exposure of sensitive information or unauthorized account access. 
       

      AFFECTED PRODUCTS

      All versions of Mozilla Firefox prior to 134.

      Note: This issue only affected Android operating systems. Other operating systems are unaffected.
       

      RECOMMENDATIONS


      Users are strongly advised to upgrade to Mozilla Firefox version 134 or later to mitigate this vulnerability.
       

      REFERENCES

    https://nvd.nist.gov/vuln/detail/CVE-2025-0244

    https://www.mozilla.org/en-US/security/advisories/mfsa2025-01/

    https://feedly.com/cve/CVE-2025-0244

     

  • Google Chrome Type Confusion Vulnerability (CVE-2025-0291)

    CVSS SCORE: 8.3 High

    BACKGROUND

    CVE-2025-0291 is a high-severity vulnerability identified in Google Chrome's V8 JavaScript engine that can lead to remote code execution. This vulnerability stems from a Type Confusion flaw, where the program incorrectly treats data as a different type than intended. Such flaws can allow attackers to manipulate memory, potentially resulting in data theft, system crashes, or full device takeover.        

    IMPACT

    •     Allow attackers to run arbitrary code on a user's system. 
    •      Potentially leads to data theft, system compromise, or further attacks by taking over the affected device.
     

    AFFECTED PRODUCTS


    •      Google Chrome web browser versions prior to 131.0.6778.264 across all platforms (Windows, Mac and Linux) except iOS.
     

    RECOMMENDATIONS

    Users are advised to immediately update their Chrome browsers to the latest version:

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.