Fortinet has released a patch for a critical remote code execution vulnerability that has been exploited in FortiOS.
The security vulnerability number is CVE-2024-21762 and affects FortiOS versions 6.0, 6.2, 6.4, 7.0, 7.2, and 7.4. Patches have been released for each of the affected versions (except 6.0)
It is recommended that 6.0 users migrate to a newer version. FortiOS 7.6 is not affected by this vulnerability.
CVE-2024-21762 is a zero-day vulnerability that Fortinet says "may have been exploited in the wild".
The vulnerability is described as an out-of-bounds write issue that can be exploited by an unauthenticated, remote attacker to execute arbitrary code using a specially crafted HTTP request.
Fortinet Issues FortiOS Zero-Day Threat Warning
Previous: 能源巨头遭勒索软件攻击TB级数据存在泄露风险
Next: 人工智能AI主播开启虚拟主播新时代