Attacks Exploiting Vulnerabilities in FortiOS and FortiProxy

Attacks Exploiting Vulnerabilities in FortiOS and FortiProxy

In recent weeks, attacks have emerged that exploit a new zero-day vulnerability in FortiOS and FortiProxy systems. This vulnerability, designated CVE-2024-55591, affects FortiOS versions 7.0.0 through 7.0.16, FortiProxy versions 7.0.0 through 7.0.19, and FortiProxy versions 7.2.0 through 7.2.12. Successful exploitation of this vulnerability allows attackers to gain super-administrator privileges by sending requests to the Node.js WebSocket module.

Fortinet stated that attackers currently exploiting this vulnerability are creating randomly generated administrator or local user accounts on compromised devices. These users are added to existing SSL VPN user groups, modify firewall settings and other policies, and then connect to the SSL VPN using these falsely created accounts, thereby gaining access to the internal network

According to a report by Arctic Wolf, this attack has been ongoing since mid-November 2024. The attacks target FortiGate firewalls whose management interfaces are accessible from the internet. The report also states that the attacks involved unauthorized administrative access, the creation of new accounts, authentication to the SSL VPN, and other configuration changes

Although Fortinet has not disclosed details about the campaign, Arctic Wolf claims that widespread exploitation of this vulnerability is highly likely. Block access to the administrative interface on public interfaces. As a temporary measure, Fortinet recommends disabling the HTTP/HTTPS administrative interface or restricting access to these interfaces using local policies.

Several IP addresses appeared in log records during these attacks: 1.1.1.1, 127.0.0.1, 2.2.2.2, 8.8.8.8, and 8.8.4.4. These addresses may indicate that a device was targeted. To detect exploitation of this vulnerability, both companies recommend checking logs for entries containing randomly generated IP addresses and usernames.

Example:

type="event" subtype="system" level="information" vd="root" logdesc="Admin login successful" sn="1733486785" user="admin" ui="jsconsole" method="jsconsole" srcip=1.1.1.1 dstip=1.1.1.1 action="login" status="success" reason="none" profile="super_admin" msg="Administrator admin logged in successfully from jsconsole"

Fortinet has also released security patches for another critical vulnerability, CVE-2023-37936, which allows remote attackers to execute unauthorized code via malformed cryptographic requests. In addition, in December 2024, Volexity announced that Chinese hackers are using a custom tool to carry out post-exploitation attacks on FortiClient for Windows.

This incident serves as a warning for organizations to pay increased attention to the security of their firewalls, regularly update their devices, and restrict public access to administrative interfaces until the vulnerability is fully patched.

Leave a Reply

Your email address will not be published. Required fields are marked *