Skip to main content
bmali
Staff
Staff
September 23, 2024

Outbreak Alert: GeoServer RCE Attack

  • September 23, 2024
  • 0 replies
  • 423 views

FortiRecon Digital Risk Protection (DRP), a SaaS-based service, includes External Attack Surface Management, Brand Protection, and Adversary Centric Intelligence.

Adversary Centric Intelligence (ACI): leverages FortiGuard Threat Analysis to provide comprehensive coverage of dark web, open-source, and technical threat intelligence, including threat actor insights to enable organizations to respond proactively assess risks, respond faster to incidents, better understand their attackers, and guard assets.

The Vulnerability Intelligence Module under Adversary Centric Intelligence (ACI) provides a realistic view of the impact of the vulnerability based upon chatter and discussion of the same across various external sources such as Darkweb, social media, News / Blogs etc.

CVE ID CVE-2024-36401
CVE Title GeoServer GeoTools Eval Injection Vulnerability
NVD Severity CRITICAL
FortiRecon Severity CRITICAL
FortiRecon Score 100/100
Exploited Yes
Exploited by Ransomware Group(s) No
Exploited by APT Group(s) Yes (earth baxia)
Included in CISA KEV List Yes
Available working exploit(s) 2
Available POC exploit(s) 12
Darknet Mention(s) 0
Telegram Mention(s) 3 (Life-Hack - Жизнь-Взлом / Хакинг, Hacker Forum™, لواء محمد ﷺ)
FortiRecon Intelligence Reporting(s) 2 (Technical Intelligence), 8 (OSINT), 1 (FortiGuard Research)
Vendor Advisory:

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.