FortiManager Critical CVE-2024-47575 “FortiJump” Allows RCE
ID: 39ce1fbe-5ae3-55af-8c3e-01cd72ebea11
STIX ID: report--39ce1fbe-5ae3-55af-8c3e-01cd72ebea11
Feed Name: Kudelski Security
On 2024-10-23 Fortinet disclosed CVE-2024-47575 (“FortiJump”), a critical unauthenticated vulnerability in the FortiManager fgfmd daemon that has been exploited in the wild to retrieve and exfiltrate managed-device configurations, IPs and hashed credentials; Mandiant observed activity attributed to UNC5820 and reported compressed archives of configuration files being transferred externally. The advisory lists affected FortiManager/FortiManager Cloud versions, describes the files and APIs targeted, and provides mitigation steps including immediate upgrades, certificate restrictions, and local-in policy workarounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
