We've had to write the word "Fortinet" so often lately that we're considering making a macro just to make our lives a little easier after what the company's reps will surely agree has been a week sent from hell. It all culminated this Friday with the disclosure of yet another critical security vulnerability in FortiOS, impacting its SSL VPN. Tracked as CVE-24-21762, the 9.6 severity out-of-bounds write issue allows for remote unauthenticated attackers to achieve code execution. There's also evidence to suggest it's already been exploited as a zero-day. Security researchers have urged users to patch vulnerable VPNs as soon as possible since the vulnerability is understood to be easily exploitable. There are various different affected versions of FortiOS and different patches available. The vulnerability also impacts unsupported versions, so now is definitely the time to make that upgrade if FortiOS 6.0.x is still running. The only workaround recommended by Fortinet is to disable the SSL VPN. Disabling webmode won't mitigate the vulnerability, it said. Other vulnerabilities were also disclosed alongside it, such as CVE-2024-23113 – a critical RCE bug in FortiOS fgfmd daemon, but these haven't been exploited in the wild. Some of you Reg readers will have been following the Fortinet-related coverage this week and perused the story about a confusing double bug disclosure on February 6. This was just the start of hell week. The story immediately attracted our attention since it's n...
A look at Fortinet's week to forget
The Register
·Connor Jones
·Published Feb 9, 2024
·Updated
Affected Software
3 affected components
Fortinet FortiOS=6.0.x
Fortinet FortiOS
Fortinet FortiSIEM
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a challenging week for Fortinet, marked by significant security issues.
2
What security implications are discussed in the article?
The article highlights vulnerabilities in Fortinet products that could potentially expose users to security risks.
3
What products or software are affected by the reported issues?
The affected products include Fortinet FortiOS version 6.0.x and Fortinet FortiSIEM.
4
What specific version of FortiOS is mentioned in the article?
The article specifically mentions FortiOS version 6.0.x as affected.
5
What was the overall sentiment expressed about Fortinet's recent challenges?
The article conveys a sentiment of frustration regarding the frequency and severity of Fortinet's security disclosures.