216.73.216.6

Investigating FortiManager Zero-Day Exploitation (CVE-2024-47575)

· Published 24/10/2024 11:31 · Modified 28/10/2024 12:55

Export JSON

Essential information

Published
24/10/2024 11:31
Modified
28/10/2024 12:55
Tags
2024-10-24 CVE-2024-47575 configuration-exfiltration cyber espionage exploitation fortigate fortimanager network-security vulnerability zero-day
Related entities
1 vulnerabilities (cve), 4 observables, 1 intrusion sets (apt), 10 techniques (mitre)

Description

A new threat cluster, UNC5820, has been observed exploiting a in appliances across multiple industries. The allows unauthorized execution of arbitrary code or commands on vulnerable devices. The attackers staged and exfiltrated configuration data from managed devices, potentially enabling further compromise. attempts were first detected on June 27, 2024, with a second attempt on September 23, 2024. The threat actor added an unauthorized device to the console and exfiltrated compressed archives containing sensitive configuration files. While no evidence of lateral movement has been found, organizations with exposed devices are urged to conduct immediate forensic investigations.

External references