CISA says critical Fortinet RCE flaw now exploited in attacks

Teilen:

Today, CISA revealed that attackers actively exploit a critical FortiOS remote code execution (RCE) vulnerability in the wild.

The flaw (CVE-2024-23113) is caused by the fgfmd daemon accepting an externally controlled format string as an argument, which can let unauthenticated threat actors execute commands or arbitrary code on unpatched devices in low-complexity attacks that don’t require user interaction.

As Fortinet explains, the vulnerable fgfmd daemon runs on FortiGate and FortiManager, handling all authentication requests and managing keep-alive messages between them (as well as all resulting actions like instructing other processes to update files or databases).

CVE-2024-23113 impacts FortiOS 7.0 and later, FortiPAM 1.0 and higher, FortiProxy 7.0 and above, and FortiWeb 7.4.

The company disclosed and patched this security flaw in February when it advised admins to remove access to the fgfmd damon for all interfaces as a mitigation measure designed to block potential attacks.

“Note that this will prevent FortiGate discovery from FortiManager. Connection will still be possible from FortiGate,” Fortinet said.

“Please also note that a local-in policy that only allows FGFM connections from a specific IP will reduce the attack surface but it won’t prevent the vulnerability from being exploited from this IP. As a consequence, this should be used as a mitigation and not as a complete workaround.”

Federal agencies ordered to patch within three weeks

While Fortinet has yet to update its February advisory to confirm CVE-2024-23113 exploitation, CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog on Wednesday.

U.S. federal agencies are now also required to secure FortiOS devices on their networks against these ongoing attacks within three weeks, by October 30, as required by the binding operational directive (BOD 22-01) issued in November 2021.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” the cybersecurity agency warned.

The Dutch Military Intelligence and Security Service (MIVD) warned in June that Chinese hackers exploited another critical FortiOS RCE vulnerability (CVE-2022-42475) between 2022 and 2023 to breach and infect at least 20,000 Fortigate network security appliances with malware.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:05 am, Juni 26, 2025
Wetter-Symbol 19°C
L: 18° | H: 20°
broken clouds
Luftfeuchtigkeit: 79 %
Druck: 1009 mb
Wind: 10 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 68%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:44 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 1 mm 100% 15 mph 85 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 27°°C 0 mm 0% 13 mph 66 % 1022 mb 0 mm/h
Sa. Juni 28 10:00 pm
Wetter-Symbol
17° | 28°°C 0 mm 0% 10 mph 87 % 1024 mb 0 mm/h
So. Juni 29 10:00 pm
Wetter-Symbol
19° | 33°°C 0 mm 0% 10 mph 83 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
20° | 35°°C 0 mm 0% 13 mph 60 % 1019 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 8 mph 80 % 1009 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 79 % 1009 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
22° | 23°°C 0 mm 0% 13 mph 62 % 1010 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
20° | 20°°C 0.81 mm 81% 10 mph 85 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 1 mm 100% 15 mph 36 % 1012 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 21°°C 0.08 mm 8% 14 mph 36 % 1015 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 48 % 1018 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 59 % 1020 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,370.53
1.28%
Ethereum(ETH)
€2,129.37
1.38%
Fesseln(USDT)
€0.86
0.00%
XRP(XRP)
€1.88
0.82%
Solana(SOL)
€125.11
0.06%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.142112
-0.23%
Shiba Inu(SHIB)
€0.000010
0.23%
Pepe(PEPE)
€0.000009
-4.75%
Nach oben scrollen