FortiOS SSL VPN Vulnerability Actively Exploited in the Wild (2024)

On February 8, 2024, Fortinet issued a security advisory regarding a critical remote code execution (RCE) vulnerability impacting FortiOS SSL VPN. The vulnerability, CVE-2024-21762, allows threat actors to run arbitrary code or commands via specially crafted HTTP requests.

The FortiOS SSL VPN vulnerability potentially enables threat actors to execute several cyber attacks. Businesses running FortiOS SSL VPN should take immediate remediation steps.

On February 9, 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the FortiOS SSL VPN vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and announced attackers were actively exploiting it in the wild.

At the time of publication, CISA’s advisory cautioned that Fortinet had not provided additional details about attacks, but noted that threat actors often exploit vulnerabilities in Fortinet devices.

Fortinet also patched two separate critical RCE vulnerabilities the week of February 9, 2024, potentially creating confusion among businesses regarding which devices were vulnerable to which CVE.

Businesses running FortiOS SSL VPN should immediately follow the vendor's guidance to patch their devices to the appropriate version. If they cannot immediately patch, they should instead disable ‘sslvpnd’ as a workaround. However, disabling ‘sslvpnd’ will make the VPN device unusable.

As a precautionary measure, we recommend taking impacted Fortinet devices offline until they have been updated to the newest version of FortiOS. Fortinet has provided instructions in their security advisory, which includes a complete list of impacted versions and what patches to apply.

Coalition external scans cannot detect which firmware version a business is running. Any policyholder with questions or concerns regarding their Fortinet device or the FortiOS SSL VPN vulnerability can contact our Security Support Center.

Insurance products referenced herein are offered by Coalition Insurance Solutions, Inc. (“CIS”), a licensed insurance producer with its principal place of business in San Francisco, CA (Cal. license #0L76155), acting on behalf of a number of unaffiliated insurance companies. A list of our admitted carriers is available here. Complete license information for CIS is available here. Insurance products offered through CIS may not be available in all states. All insurance products are governed by the terms and conditions set forth in the applicable insurance policy. Please see a copy of your policy for the full terms and conditions. Any information on this communication does not in any way alter, supplement, or amend the terms and conditions of the applicable insurance policy and is intended only as a brief summary of such insurance products. Policy obligations are the sole responsibility of the issuing insurance carrier. The descriptions provided herein are solely for informational purposes and are not to be construed as advice of any kind or the rendering of consulting, financial, legal, or other professional services from Coalition. Any action you take upon the information contained herein is strictly at your own risk. Coalition will not be liable for any losses and damages in connection with your use or reliance upon the information.
FortiOS SSL VPN Vulnerability Actively Exploited in the Wild (2024)
Top Articles
Does debt relief hurt your credit score?
The Best Stocks to Buy and Hold in May 2024 | The Motley Fool
Katie Pavlich Bikini Photos
UPS Paketshop: Filialen & Standorte
Bj 사슴이 분수
jazmen00 x & jazmen00 mega| Discover
Rondale Moore Or Gabe Davis
Puretalkusa.com/Amac
Corpse Bride Soap2Day
Ncaaf Reference
Southland Goldendoodles
Caroline Cps.powerschool.com
Power Outage Map Albany Ny
Healing Guide Dragonflight 10.2.7 Wow Warring Dueling Guide
Www Craigslist Com Phx
Buy PoE 2 Chaos Orbs - Cheap Orbs For Sale | Epiccarry
Canvas Nthurston
Itziar Atienza Bikini
Lowe's Garden Fence Roll
Petco Vet Clinic Appointment
Airrack hiring Associate Producer in Los Angeles, CA | LinkedIn
Acts 16 Nkjv
Lakewood Campground Golf Cart Rental
Free Personals Like Craigslist Nh
Xfinity Outage Map Fredericksburg Va
Manuela Qm Only
Wrights Camper & Auto Sales Llc
Culver's.comsummerofsmiles
Claio Rotisserie Menu
Motorcycle Blue Book Value Honda
Deepwoken: Best Attunement Tier List - Item Level Gaming
Busted! 29 New Arrests in Portsmouth, Ohio – 03/27/22 Scioto County Mugshots
Craigs List Tallahassee
Gr86 Forums
Craigslist Org Sf
Cross-Border Share Swaps Made Easier Through Amendments to India’s Foreign Exchange Regulations - Transatlantic Law International
Bbc Gahuzamiryango Live
Tiny Pains When Giving Blood Nyt Crossword
Craigs List Palm Springs
Casamba Mobile Login
1Exquisitetaste
Immobiliare di Felice| Appartamento | Appartamento in vendita Porto San
Dr Mayy Deadrick Paradise Valley
Human Resources / Payroll Information
Lesson 5 Homework 4.5 Answer Key
Theatervoorstellingen in Nieuwegein, het complete aanbod.
Used Sawmill For Sale - Craigslist Near Tennessee
Okta Hendrick Login
Dmv Kiosk Bakersfield
O.c Craigslist
King Fields Mortuary
Ranking 134 college football teams after Week 1, from Georgia to Temple
Latest Posts
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 6125

Rating: 4.9 / 5 (49 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.