• News/
  • https://www.theregister.com/2024/03/18/more_than_133000_fortinet_appliances/

133k+ Fortinet appliances still vulnerable to CVE-2024-21762

The Register
·
Connor Jones
·
Published Mar 18, 2024
·
Updated

The volume of Fortinet boxes exposed to the public internet and vulnerable to a month-old critical security flaw in FortiOS is still extremely high, despite a gradual increase in patching. According to security nonprofit Shadowserver's latest data, the number of Fortinet appliances vulnerable to CVE-2024-21762 stands at more than 133,000 – down only slightly from more than 150,000 ten days prior. Fortinet patched CVE-2024-21762 in early February, well over a month ago. It's a 9.6-out-of-10 severity vulnerability that leads to remote code execution (RCE) and appeared front and center during Fortinet's week to forget last month. The biggest number of exposures is in Asia, with 54,310 appliances still vulnerable to the critical RCE bug, the data shows. North America and Europe fill the second and third spots with 34,945 and 28,058 respectively, while South America, Africa, and Oceania comprise the remainder. The number of exposed SSL VPNs illustrates the wide attack surface for the critical vulnerability, one that's already known to be actively exploited. When it was first disclosed by Fortinet, the vendor said there was evidence of it being used as a zero day. The US government's Cybersecurity and Infrastructure Security Agency (CISA) soon corroborated this by adding it to the Known Exploited Vulnerability (KEV) catalog, thereby requiring all federal agencies to patch it within a tight deadline. Proof of concepts are now relatively widely available online, meaning the likelihoo...

Read full article

Affected Software

2 affected components
Fortinet FortiOS
Fortinet FortiClient Endpoint Management Server (EMS)
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the continued vulnerability of over 133,000 Fortinet appliances to a critical security flaw in FortiOS.

2

What security implications are discussed?

The article highlights the risk associated with a critical flaw, CVE-2024-21762, that leaves numerous Fortinet devices exposed to potential exploitation.

3

How many Fortinet appliances are still vulnerable?

More than 133,000 Fortinet appliances remain vulnerable to the recently identified security flaw.

4

What specific Fortinet products are mentioned as affected?

The affected products include FortiOS and FortiClient Endpoint Management Server (EMS).

5

Is there an indication of progress in patching these vulnerabilities?

While there has been a gradual increase in patching, the volume of exposed devices remains alarmingly high.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203