A critical vulnerability in FortiManager, which is being actively exploited, poses a severe threat to organizations. This flaw allows remote attackers to execute arbitrary code or commands without authentication. Given the widespread use of FortiManager in managing Fortinet devices, a successful attack could compromise network operations, exfiltrate sensitive data, or disrupt critical services.
| Product | Fortinet FortiManager |
| Date | 2024-11-15 14:31:13 |
| Information |
|
Technical Summary
A “missing authentication for critical function” vulnerability (CWE-306) in the fgfmd daemon of FortiManager allows unauthenticated remote attackers to execute arbitrary code or commands via specially crafted requests. This issue also affects FortiAnalyzer models with FortiManager features enabled. Exploitation of this flaw could allow unauthorized device registration and the compromise of Fortinet devices.
Recommendations
- Update FortiManager to the latest corrected version (see the list of fixes for each major version here).
- Enable controls: for supported versions, enable
fgfm-deny-unknownto block connections from unregistered devices. - Deploy custom certificates: configure and apply a custom CA certificate for communications between FortiManager and FortiGate.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
