Skip to content
COOEY

EXPOSURES › CVE-2024-21762

CVE-2024-21762

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-02-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-21762 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Fortinet FortiOS suffered a critical out-of-bounds write vulnerability allowing unauthenticated remote code execution.

An unauthenticated remote attacker could execute arbitrary code via crafted HTTP requests, enabling ransomware deployment and network compromise. DIB organizations must patch FortiOS immediately and monitor for exploitation attempts, as this flaw was actively exploited in the wild and linked to ransomware campaigns.

Shame score — A critical unauthenticated RCE in a core firewall OS was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and threat detection.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.