216.73.216.197

Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls

· Published 11/01/2025 02:10 · Modified 13/01/2025 10:44

Export JSON

Essential information

Published
11/01/2025 02:10
Modified
13/01/2025 10:44
Tags
2025-01-11 firewall fortigate fortinet jsconsole lateral movement ssl vpn vulnerability scanning zero-day
Related entities
5 techniques (mitre)

Description

A recent campaign targeting devices with exposed management interfaces has been observed. The threat actors gained unauthorized access to the firewalls' administrative controls, created new accounts, established connections, and made various configuration changes. While the initial access vector remains unconfirmed, a vulnerability is highly suspected. The campaign progressed through four phases: , reconnaissance, configuration, and . Affected firmware versions ranged from 7.0.14 to 7.0.16. The attackers used sessions with spoofed IP addresses and made suspicious configuration changes. Organizations are urged to disable management access on public interfaces immediately to mitigate the risk.

External references