logo

Investigating FortiManager Zero-Day Exploitation (CVE-2024-47575)

ID: ae1e392b-a13d-5b5f-a639-6a25dbc9a636

STIX ID: report--ae1e392b-a13d-5b5f-a639-6a25dbc9a636

Feed Name: Google Cloud Threat Intelligence

Threat Score
75/100

Date Published: 2024-10-23

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant and Fortinet investigated mass exploitation of FortiManager appliances via CVE-2024-47575 beginning as early as June 27, 2024, by a threat cluster tracked as UNC5820; the actor staged and exfiltrated FortiGate configuration data (including FortiOS hashed passwords) from 50+ devices, with observed inbound activity from 45.32.41.202 on TCP/541 and a staged archive at /tmp/.tm, and organizations with internet-exposed FortiManager instances are advised to perform immediate forensic investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.