A zero-day flaw is likely to blame for a series of recent attacks on Fortinet FortiGate firewall devices that have management interfaces exposed on the public Internet. Attackers are targeting the devices to make unauthorized administrative logins and other configuration changes, create new accounts, and perform SSL VPN authentication, researchers have found. Researchers at Arctic Wolf have been tracking the campaign since they first noticed suspicious activity on FortiGate devices in early December, they revealed in a recent blog post. They observed threat actors gaining access to management interfaces on affected firewalls — the firmware versions of which ranged between 7.0.14 and 7.0.16 — and altering their configurations. Moreover, in compromised environments, attackers also were using DCSync to extract credentials. Artic Wolf released a security bulletin in December upon discovery of the campaign, while the recent blog post revealed more in-depth details, including the attackers likely exploiting a zero-day flaw. However, they have not "definitively confirmed" this initial access vector, though the compressed timeline across affected organizations as well as firmware versions affected by the campaign suggest that attackers are exploiting an as-yet-undisclosed vulnerability, according to the Arctic Wolf researchers. Victims of the campaign did not represent a specific sector or organization size, suggesting "that the targeting was opportunistic in nature rather than bein...
Zero-Day Security Bug Likely Fueling Fortinet Firewall Attacks
Dark Reading
·Elizabeth Montalbano
·Published Jan 14, 2025
·Updated
Affected Software
6 affected components
Fortinet FortiGate=7.0.14
Fortinet FortiGate=7.0.15
Fortinet FortiGate=7.0.16
Fortinet FortiGate=7.0.14
Fortinet FortiGate=7.0.15
Fortinet FortiGate=7.0.16
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day security flaw potentially causing attacks targeting Fortinet FortiGate firewall devices.
2
What security implications are discussed?
The article highlights the risk of unauthorized administrative access due to exposed management interfaces on FortiGate firewalls.
3
What products or software are affected?
The affected products are Fortinet FortiGate firewall devices, specifically versions 7.0.14, 7.0.15, and 7.0.16.
4
How are the attackers exploiting this vulnerability?
Attackers are exploiting the zero-day flaw to compromise FortiGate devices with publicly accessible management interfaces.
5
What should users of affected FortiGate versions do?
Users should immediately assess their firewall configurations and apply any available security updates to mitigate the threat.