Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch

    FortiManager May Still Be Vulnerable Despite ‘FortiJump’ Patch

    November 4, 2024

    FortiManager FortiJump vulnerability exploit

    The ‘FortiJump’ vulnerability in Fortinet’s FortiManager management platform may not have been completely fixed by the company’s patch issued last month.

    A screen recording posted to X (formerly known as Twitter) today by WatchTowr suggested that the vulnerability – CVE-2024-47575 – can still be exploited.

    Cyble threat intelligence researchers reported last week that 62,000 vulnerable FortiManager instances were exposed to the internet, indicating significant enterprise exposure to this 9.8-severity vulnerability.

    “[D]espite all the buzz about FortiManager – the saga is about to continue,” WatchTowr said. “Please, remove this from the Internet *even if fully patched*”

    The FortiJump Saga Continues

    Reports of an exploited zero-day vulnerability in FortiManager were circulating more than a week before the CVE was officially reported on October 23.

    That created confusion among security researchers and even some FortiManager customers, but Cyble noted that Fortinet had sent clients an advisory a week before the vulnerability was officially disclosed, and that communication contained recommended mitigations too. However, some FortiManager customers said they hadn’t received that communication, suggesting a need for Fortinet to revisit its advisory procedures.

    In a blog post that was published the same day as the CVE, Mandiant said it had been working with Fortinet on the issue and noted that the vulnerability – classified as a “missing authentication for critical function” weakness (CWE-306) – had been exploited more than 50 times since at least late June by a new threat actor dubbed “UNC5820.”

    “UNC5820 staged and exfiltrated the configuration data of the FortiGate devices managed by the exploited FortiManager,” Mandiant said. “This data contains detailed configuration information of the managed appliances as well as the users and their FortiOS256-hashed passwords. This data could be used by UNC5820 to further compromise the FortiManager, move laterally to the managed Fortinet devices, and ultimately target the enterprise environment.”

    The post noted that data sources analyzed by the investigators “did not record the specific requests that the threat actor used to leverage the FortiManager vulnerability. Additionally, at this stage of our investigations there is no evidence that UNC5820 leveraged the obtained configuration data to move laterally and further compromise the environment.”

    Still, a commenter on a Reddit thread discussing the latest revelation noted, “For everyone running one anyway the best solution is rebuilding it from scratch and never connect the instance to the internet, at least put something in front of it and only let trusted IPs connect.”

    Also read: Nearly 1 Million Vulnerable Fortinet, SonicWall Devices Exposed to the Web

    Fortinet Has Updated FortiJump Advisory 8 Times

    The Cyber Express asked Fortinet for any comment or mitigations in response to WatchTowr’s claim that FortiManager remains vulnerable, but no response had been received as of publication time.

    CISA issued an alert on October 30 stating that Fortinet had updated its guidance (PSIRT FG-IR-24-423) on the vulnerability, which includes a number of allowlisting and denylisting steps to prevent the addition and registration of unauthorized devices in addition to recovery methods. According to Fortinet’s timeline at the bottom of the guidance page, the most substantive changes to the document appeared to have occurred between Oct. 23-28:

    • 2024-10-23: Add FortiManager Cloud fixes
    • 2024-10-24: Added workarounds to block the addition of unauthorized devices via syslog or FDS
    • 2024-10-24: Added 195.85.114.78 in IoCs
    • 2024-10-25: Added note about log entries IoCs
    • 2024-10-28: Added link to “Best Practices for Maintaining Secure Credentials”
    • 2024-10-28: Added note in workaround 1. (FMG Cloud recommended workaround)
    • 2024-10-30: Added IoCs (4 IP addresses and 1 SN)
    • 2024-11-04: Removed duplicate IP addresses

     

    Source: Read More

    Hostinger
    Facebook Twitter Reddit Email Copy Link
    Previous Article使用 MongoDB 8.0 的四大理由
    Next Article Empowering systemic racism research at MIT and beyond

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 16, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-47916 – Invision Community Themeeditor Remote Code Execution

    May 16, 2025
    Leave A Reply Cancel Reply

    Hostinger

    Continue Reading

    Microsoft brings Teams Phone to Dynamics 365 Contact Center

    Operating Systems

    Querying and writing to MySQL and MariaDB from Amazon Aurora and Amazon RDS for PostgreSQL using the mysql_fdw extension, Part 2: Handling foreign objects

    Databases

    Tockler tracks time by monitoring your active window title

    Linux

    mogwai – view library for creating GUI applications

    Development

    Highlights

    Development

    ZLoader Malware Evolves with Anti-Analysis Trick from Zeus Banking Trojan

    May 1, 2024

    The authors behind the resurfaced ZLoader malware have added a feature that was originally present in the Zeus banking trojan…

    LiteLLM: Call 100+ LLMs Using the Same Input/Output Format

    August 11, 2024

    An $800 Snapdragon X Elite laptop is the best reason not to bother buying a MacBook Air

    March 25, 2025

    Representative Line: One More Parameter, Bro

    November 7, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.