Skip to content

FortiGate SSL VPN vulnerabilities

Again and again and again, Fortinet has published critical vulnerability in FortiOS for SSL VPN CVE-2024-21762:

A out-of-bounds write vulnerability [CWE-787] in FortiOS may allow a remote unauthenticated attacker to execute arbitrary code or command via specially crafted HTTP requests.
Workaround : disable SSL VPN (disable webmode is NOT a valid workaround)
Note: This is potentially being exploited in the wild.

Let’s summarize last years:

  • 2021 – CVE-2021-26109, CVE-2021-26108
  • 2022 – CVE-2022-29055, CVE-2022-42475
  • 2023 – CVE-2023-22640, CVE-2023-27997

All above had high or critical severity, required immediate patching. SSL VPN is internet facing service usually and how dangerous it is, see below:

https://therecord.media/dutch-find-chinese-hackers-networks-fortinet

My advice… For remote access as protocol can be used ssl or ipsec, so just use IPsec. So far, no vulnerabilities here 🙂

Join the conversation

Your email address will not be published. Required fields are marked *