URGENT: Zero-Day Attack Lets Hackers Seize Control of Fortinet Firewalls – Patch Now


Critical Zero-Day Vulnerability Threatens Fortinet Firewalls

A new authentication bypass zero-day vulnerability (CVE-2024-55591) is actively being exploited to compromise Fortinet firewalls and enterprise networks. The vulnerability affects FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12.

Impact and Exploitation
Attackers can gain super-admin privileges through malicious requests to the Node.js websocket module. The exploitation allows criminals to:
– Create random admin users
– Modify SSL VPN configurations
– Alter firewall policies
– Establish tunnels to internal networks

Timeline of Attack Campaign
Arctic Wolf Labs identified four distinct phases:
1. Vulnerability Scanning: November 16-23, 2024
2. Reconnaissance: November 22-27, 2024
3. SSL VPN Configuration: December 4-7, 2024
4. Lateral Movement: December 16-27, 2024

Security Recommendations
Fortinet and security experts advise:
– Disable HTTP/HTTPS administrative interfaces
– Implement IP-based access restrictions
– Monitor logs for suspicious admin activities
– Watch for unauthorized user creation
– Check for connections from known malicious IPs: 1.1.1.1, 127.0.0.1, 2.2.2.2, 8.8.8.8, 8.8.4.4

The vulnerability was reported to Fortinet on December 12, 2024, and confirmed by FortiGuard Labs PSIRT on December 17, 2024. Organizations are urged to implement security measures immediately to protect their networks from this ongoing threat.

Share This Article