Critical zero-day vulnerability in FortiManager and FortiGate devices allows remote code execution

ISGroup Cybersecurity

FortiGate firewalls and FortiManager are widely used in enterprise networks and Managed Service Providers (MSPs) to centralize the configuration and management of security infrastructure. A recently discovered zero-day vulnerability allows attackers to exploit a weakness in the communication protocol (FGFM) between FortiGate and FortiManager devices, leading to unauthorized access to internal networks. More than 60,000 FortiManager instances are currently exposed to the Internet, increasing the risk of exploitation. Specifically, this issue allows for remote code execution (RCE) on FortiManager through the malicious registration of rogue FortiGate devices.

ProductFortinet FortiManager
Date2024-10-23 15:49:14
Information
  • Active Exploitation

Technical Summary

The vulnerability resides in the FGFM protocol (port 541), which enables communication between FortiGate firewalls and FortiManager. Attackers steal or reuse legitimate certificates from compromised FortiGate devices and use them to register their rogue devices within a FortiManager system. Once registered, attackers can exploit the vulnerability to achieve RCE on FortiManager. This grants them the ability to control managed FortiGate firewalls, exfiltrate configurations and credentials, and propagate further attacks within the network. The design of FGFM supports NAT traversal, meaning that attackers who compromise a single managed firewall can move laterally between FortiManager and other devices in the managed network, potentially compromising the entire infrastructure. Malicious actors, including state-sponsored groups, have been observed exploiting this vulnerability since early 2024.

Recommendations

  • Restrict access to FortiManager (port 541) by allowing only trusted IP addresses.
  • Configure FortiManager to reject unknown serial numbers and prevent the addition of unauthorized devices.
  • Revoke and reissue certificates used for device authentication to block any unauthorized reuse.
  • Apply security patches released by Fortinet that address this vulnerability as soon as they become available.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert