Skip to main content

Critical Vulnerability In FortiOS And FortiProxy (CVE-2024-55591)

CVSSv3 Score: Base 9.8 Critical

BACKGROUND 

Fortinet has identified a severe vulnerability in FortiOS and FortiProxy that allows unauthenticated 
remote attackers to bypass authentication mechanisms and gain “super-admin” privileges.   
Threat actors have been observed performing malicious post-exploitation activities, including the 
creation of random administrative and local user accounts, modification of system configurations 
(e.g., firewall policies), and the use of SSL VPN for unauthorized access to internal network. 

IMPACT 

  • Attackers can create new administrative and local user accounts with random usernames, resulting in unauthorized access.
  • Attackers can access the SSL VPN with newly created local user accounts to establish a connection to the internal network.
  • Attackers can gain control of the affected system and perform administrative tasks such as: 
    o Adding users to existing or new SSL VPN user groups 
    o Modifying configurations, including SSL VPN settings 
    o Adding or changing firewall policies 
    o Altering or removing system configurations 
    o Deploying malicious payloads

AFFECTED PRODUCTS

 ProductAffected Versions
1FortiOS7.0.0 through 7.0.16
2FortiProxy7.0.0 through 7.0.19
3FortiProxy7.2.0 through 7.2.12

RECOMMENDATIONS

  • Upgrade the affected versions to the fixed versions as soon as possible.
  • If immediate updates are not possible, implement the following workarounds:
    • Disable HTTP/HTTPS administrative interface or limit IP Addresses that can reach the administrative interface via local-in policies.
    • Remove the firewall’s web-based management interface from the public internet.
    • Ensure all connections to the device are monitored, and that audit logging for the device is enabled.
    • If required for operations, use ACLs to limit what IP addresses can access the port. This can be done directly on the device via the "my_allowed_addresses" configuration setting. 

Note: Detailed recommended steps to follow can be found in Fortinet’s website at https://fortiguard.fortinet.com/psirt/FG-IR-24-535

REFERENCES

https://fortiguard.fortinet.com/psirt/FG-IR-24-535

https://nvd.nist.gov/vuln/detail/CVE-2024-55591

https://www.linkedin.com/pulse/fortinet-patches-zero-day-vulnerability-fortios-eotxe/

https://www.bleepingcomputer.com/news/security/fortinet-warns-of-auth-bypass-zero day-exploited-to-hijack-firewalls/

https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2024-55591 fortinet-fortios-fortiproxy-zero-day/

 

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.