CISA says critical Fortinet RCE flaw now exploited in attacks

Share:

Today, CISA revealed that attackers actively exploit a critical FortiOS remote code execution (RCE) vulnerability in the wild.

The flaw (CVE-2024-23113) is caused by the fgfmd daemon accepting an externally controlled format string as an argument, which can let unauthenticated threat actors execute commands or arbitrary code on unpatched devices in low-complexity attacks that don’t require user interaction.

As Fortinet explains, the vulnerable fgfmd daemon runs on FortiGate and FortiManager, handling all authentication requests and managing keep-alive messages between them (as well as all resulting actions like instructing other processes to update files or databases).

CVE-2024-23113 impacts FortiOS 7.0 and later, FortiPAM 1.0 and higher, FortiProxy 7.0 and above, and FortiWeb 7.4.

The company disclosed and patched this security flaw in February when it advised admins to remove access to the fgfmd damon for all interfaces as a mitigation measure designed to block potential attacks.

“Note that this will prevent FortiGate discovery from FortiManager. Connection will still be possible from FortiGate,” Fortinet said.

“Please also note that a local-in policy that only allows FGFM connections from a specific IP will reduce the attack surface but it won’t prevent the vulnerability from being exploited from this IP. As a consequence, this should be used as a mitigation and not as a complete workaround.”

Federal agencies ordered to patch within three weeks

While Fortinet has yet to update its February advisory to confirm CVE-2024-23113 exploitation, CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog on Wednesday.

U.S. federal agencies are now also required to secure FortiOS devices on their networks against these ongoing attacks within three weeks, by October 30, as required by the binding operational directive (BOD 22-01) issued in November 2021.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” the cybersecurity agency warned.

The Dutch Military Intelligence and Security Service (MIVD) warned in June that Chinese hackers exploited another critical FortiOS RCE vulnerability (CVE-2022-42475) between 2022 and 2023 to breach and infect at least 20,000 Fortigate network security appliances with malware.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:55 am, Jun 26, 2025
weather icon 18°C
L: 17° | H: 19°
scattered clouds
Humidity: 82 %
Pressure: 1010 mb
Wind: 11 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 19°°C 1 mm 100% 15 mph 84 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 27°°C 0 mm 0% 13 mph 66 % 1022 mb 0 mm/h
Sat Jun 28 10:00 pm
weather icon
17° | 28°°C 0 mm 0% 10 mph 87 % 1024 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
19° | 33°°C 0 mm 0% 10 mph 83 % 1025 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
20° | 35°°C 0 mm 0% 13 mph 60 % 1019 mb 0 mm/h
Today 7:00 am
weather icon
18° | 18°°C 0 mm 0% 9 mph 82 % 1010 mb 0 mm/h
Today 10:00 am
weather icon
20° | 22°°C 0 mm 0% 13 mph 74 % 1010 mb 0 mm/h
Today 1:00 pm
weather icon
19° | 20°°C 0.81 mm 81% 10 mph 84 % 1011 mb 0 mm/h
Today 4:00 pm
weather icon
24° | 24°°C 1 mm 100% 15 mph 36 % 1012 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 21°°C 0.08 mm 8% 14 mph 36 % 1015 mb 0 mm/h
Today 10:00 pm
weather icon
18° | 18°°C 0 mm 0% 10 mph 48 % 1018 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 59 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 15°°C 0 mm 0% 6 mph 66 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,278.10
1.57%
Ethereum(ETH)
€2,120.69
1.74%
Tether(USDT)
€0.86
0.00%
XRP(XRP)
€1.87
0.76%
Solana(SOL)
€124.43
0.10%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.141576
0.43%
Shiba Inu(SHIB)
€0.000010
-0.12%
Pepe(PEPE)
€0.000009
-5.28%
Scroll to Top