FortiRecon
FortiRecon is a digital risk protection (DRP) service that allows customers to gain visibility of their digital attack surface, receive targeted threat intelligence, and reduce organisational risk.
smallick
Staff
Staff
Article Id 402493

FortiRecon Digital Risk Protection (DRP), a SaaS-based service, includes External Attack Surface Management, Brand Protection, and Adversary Centric Intelligence.

Adversary Centric Intelligence (ACI): leverages FortiGuard Threat Analysis to provide comprehensive coverage of dark web, open-source, and technical threat intelligence, including threat actor insights to enable organizations to respond proactively assess risks, respond faster to incidents, better understand their attackers, and guard assets.

The Vulnerability Intelligence Module under Adversary Centric Intelligence (ACI) provides a realistic view of the impact of the vulnerability based upon chatter and discussion of the same across various external sources such as Darkweb, social media, News / Blogs etc.

CVE ID CVE-2025-32819
CVE Title A vulnerability in SMA100 allows a remote authenticated attacker with...
NVD Severity HIGH
FortiRecon Severity LOW
FortiRecon Score 15/100
Epss Score 0.00129
Exploited No
Exploited by Ransomware Group(s) No
Exploited by APT Group(s) No
Included in CISA KEV List No
Available working exploit(s) 0
Available POC exploit(s) 0
Darknet Mention(s) 0
Telegram Mention(s) 1 (SecAtor)
FortiRecon Intelligence Reporting(s) 2 (OSINT)
Vendor Advisory:

 

CVE ID CVE-2024-38475
CVE Title Apache HTTP Server Improper Escaping of Output Vulnerability
NVD Severity Not Assigned
FortiRecon Severity CRITICAL
FortiRecon Score 95/100
Epss Score 0.9355
Exploited Yes
Exploited by Ransomware Group(s) Yes
Exploited by APT Group(s) No
Included in CISA KEV List Yes
Available working exploit(s) 0
Available POC exploit(s) 4
Darknet Mention(s) 0
Telegram Mention(s) 1 (SecAtor)
FortiRecon Intelligence Reporting(s) 7 (OSINT), 4 (FortiGuard Research)
Vendor Advisory:

 

CVE ID CVE-2021-20039
CVE Title Improper neutralization of special elements in the SMA100 management interface...
NVD Severity HIGH
FortiRecon Severity HIGH
FortiRecon Score 70/100
Epss Score 0.53655
Exploited No
Exploited by Ransomware Group(s) No
Exploited by APT Group(s) No
Included in CISA KEV List No
Available working exploit(s) 1
Available POC exploit(s) 0
Darknet Mention(s) 1 (ramp)
Telegram Mention(s) 1 (SecAtor)
FortiRecon Intelligence Reporting(s) 2 (OSINT)
Vendor Advisory:

 

CVE ID CVE-2021-20038
CVE Title SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
NVD Severity CRITICAL
FortiRecon Severity CRITICAL
FortiRecon Score 95/100
Epss Score 0.94311
Exploited Yes
Exploited by Ransomware Group(s) Yes
Exploited by APT Group(s) No
Included in CISA KEV List Yes
Available working exploit(s) 0
Available POC exploit(s) 3
Darknet Mention(s) 1 (xss)
Telegram Mention(s) 1 (SecAtor)
FortiRecon Intelligence Reporting(s) 6 (OSINT), 3 (FortiGuard Research), 1 (Technical Intelligence)
Vendor Advisory:

 

CVE ID CVE-2021-20035
CVE Title SonicWall SMA100 Appliances OS Command Injection Vulnerability
NVD Severity MEDIUM
FortiRecon Severity CRITICAL
FortiRecon Score 90/100
Epss Score 0.14007
Exploited Yes
Exploited by Ransomware Group(s) Yes
Exploited by APT Group(s) No
Included in CISA KEV List Yes
Available working exploit(s) 0
Available POC exploit(s) 0
Darknet Mention(s) 0
Telegram Mention(s) 1 (SecAtor)
FortiRecon Intelligence Reporting(s) 4 (OSINT), 2 (FortiGuard Research)
Vendor Advisory:

 

Contributors