Again and again and again, Fortinet has published critical vulnerability in FortiOS for SSL VPN CVE-2024-21762:
A out-of-bounds write vulnerability [CWE-787] in FortiOS may allow a remote unauthenticated attacker to execute arbitrary code or command via specially crafted HTTP requests.
Workaround : disable SSL VPN (disable webmode is NOT a valid workaround)
Note: This is potentially being exploited in the wild.
Let’s summarize last years:
- 2021 – CVE-2021-26109, CVE-2021-26108
- 2022 – CVE-2022-29055, CVE-2022-42475
- 2023 – CVE-2023-22640, CVE-2023-27997
All above had high or critical severity, required immediate patching. SSL VPN is internet facing service usually and how dangerous it is, see below:
https://therecord.media/dutch-find-chinese-hackers-networks-fortinet
My advice… For remote access as protocol can be used ssl or ipsec, so just use IPsec. So far, no vulnerabilities here 🙂