Fortinet's week to forget: Critical vulns, disclosure screw-ups, and <em>that</em> toothbrush DDoS attack claim
ID: 7f829e24-2975-5870-8156-ef9e0cd01739
STIX ID: report--7f829e24-2975-5870-8156-ef9e0cd01739
Feed Name: The Register (Security)
The Register reports a string of Fortinet security problems, most critically CVE-24-21762 (a 9.6-severity out-of-bounds write in FortiOS SSL VPN enabling remote unauthenticated RCE with signs of in-the-wild exploitation). The article details affected FortiOS versions (including unsupported releases), available patches and limited workaround (disable SSL VPN), alongside additional disclosed CVEs, disclosure mishandling by the vendor, and reports of Chinese actors exploiting FortiGate with custom malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
