Fortinet Authentication Bypass – Critical

Share This Post

On 10/6/22 Fortinet announced an authentication bypass vulnerability in their FortiGate and FortiProxy products. This vulnerability would allow an attacker to bypass authentication access the Administrative functions of these devices and should be patched immediately.

There have been a few Fortinet related vulnerabilities over the last couple of years and organizations are often slow to patch these devices as the process can often be disruptive. However, these authentication bypass vulnerabilities are nothing to play with and should be addressed as quickly as possible.

At the moment there are approximately 100,000 of these devices that can be discovered through a Shodan search, so this has the potential to impact a lot of organizations. As is noted in the article linked below, it is unclear if all of those devices have their management portal exposed to the internet, and as a best practice these should not be exposed. As a mitigation step for this vulnerability, as well as future vulnerabilities, management interfaces should only be exposed to the internal network and limited to the devices that can access them from there.

This vulnerability is being tracked as CVE-2022-40684 and Fortinet has released a patch for it. Get that patch installed ASAP and block external traffic to those management interfaces.

Bleeping Computer: https://www.bleepingcomputer.com/news/security/fortinet-warns-admins-to-patch-critical-auth-bypass-bug-immediately/



Reach out to our incident response team for help

More To Explore

Information Security News 9-30-2024

NIST Drops Password Complexity, Mandatory Reset Rules Article Link: https://www.darkreading.com/identity-access-management-security/nist-drops-password-complexity-mandatory-reset-rules Hacker Plants False Memories in ChatGPT to Steal User Data in Perpetuity Article Link: https://arstechnica.com/security/2024/09/false-memories-planted-in-chatgpt-give-hacker-persistent-exfiltration-channel/

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.