rootpwn

Threat Intel

FortiOS SSL‑VPN RCE (CVE‑2024‑21762): Public Exploits, Patch Now

Fortinet’s FortiOS and FortiProxy software suffer a critical unauthenticated remote‑code‑execution flaw in the SSL‑VPN. Public exploit code and active attacks have been observed, with CISA confirming real‑world exploitation. Affected versions span FortiOS 6.0‑7.4.x and multiple FortiProxy releases. Apply the vendor patch immediately; if that’s not possible, disable the SSL‑VPN interface as a temporary stopgap.

Fortinet’s February 8 advisory FG‑IR‑24‑015 warned that a flaw in the SSL‑VPN component of FortiOS could allow an unauthenticated attacker to execute arbitrary code on the device. The vulnerability, catalogued as CVE‑2024‑21762, has been publicly exploited and is listed in the CISA known‑exploited‑vulnerabilities catalog.

What’s at Stake

  • Unauthenticated remote code execution on FortiOS and FortiProxy appliances.
  • Potential full device takeover, data exfiltration, or pivot to internal networks.
  • No authentication or special privileges required to trigger the flaw.

Affected Systems

  • FortiOS: 6.0 (all), 6.2.x < 6.2.16, 6.4.x < 6.4.15, 7.0.x < 7.0.14, 7.2.x < 7.2.7, 7.4.x < 7.4.3.
  • FortiProxy: 1.0 (all), 1.1 (all), 1.2 (all), 2.0.x < 2.0.14, 7.0.x < 7.0.15, 7.2.x < 7.2.9, 7.4.x < 7.4.3.

Exploitation Landscape

Public exploit code is circulating, and CISA reports active exploitation attempts. The flaw is trivial to trigger via crafted SSL‑VPN traffic.

How to Protect

  • Patch ASAP: Download the latest FortiOS and FortiProxy updates from Fortinet’s PSIRT portal (FG‑IR‑24‑015) and apply them on all affected devices.
  • Temporary Work‑Around: Disable the SSL‑VPN interface if patching cannot be performed immediately. Note that merely turning off the web interface does not mitigate the risk.
  • Verify the firmware version after patching to ensure the fix is in place.
  • Monitor logs for anomalous SSL‑VPN connections and block suspicious IPs.

Fortinet CVE-2024-21762 Remote Code Execution SSL VPN FortiOS FortiProxy Patch CISA

← All news