Skip to main content
bevvet
New Member
January 16, 2025
Question

FG-IR-24-250 / Can someone Explain?

  • January 16, 2025
  • 2 replies
  • 1566 views

hi at all,

so, fortinet got some CVE's, nevermind... Every CVE i check if its attackable to our environment, ok...
but the FG-IR-24-250 one, i dont understand the concept...

Can someone explain this to me?
How could the unauthenticated attacker access the gui, or more like, how am i vulnerable?

Could the attacker attack is, if he get access to a gui? Like if he can access the SSL VPN Portal, he can use this attack unauthenticated pordal?
or is it only possible if the attacker got access to the admin GUI?

Admin GUI isnt accessable from external, and all SSL VPN Portals the Web-mode is disabled, but as the Web-mode-Login-PAge is still accessable... so is this a way to attack?

maybe everything is lost in translation at my point, and other people understand this CVE, but the reseller and technical service provider didnt understand the attack-possibilities too...

Can someone help me to learn something?:(

2 replies

dingjerry_FTNT
Staff
Staff
January 16, 2025

Hi @bevvet ,

 

As far as I understand it, no, the attacker has no access to your FortiGate via this vulnerability.

 

This vuln only attacks your FortiGate to be crashed, using API.

Hatibi
Staff & Editor
Staff & Editor
January 16, 2025

In this case the vulnerability is CVE-2024-46666 which will cause a Denial of Service.

You are vulnerable because an adversary/attacker can craft REST API requests that will make the FortiGate unresponsive and impact any endpoints using its services.

 

You should be concerned only if you have HTTP or HTTPD services enabled on any interfaces where API requests can be sent.

You can upgrade to the versions suggested in FG-IR-24-250 .Alternatively disable HTTP/HTTPS or use local-in policies by restricting on IPs allowed access.

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.