Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bevvet
New Contributor

FG-IR-24-250 / Can someone Explain?

hi at all,

so, fortinet got some CVE's, nevermind... Every CVE i check if its attackable to our environment, ok...
but the FG-IR-24-250 one, i dont understand the concept...

Can someone explain this to me?
How could the unauthenticated attacker access the gui, or more like, how am i vulnerable?

Could the attacker attack is, if he get access to a gui? Like if he can access the SSL VPN Portal, he can use this attack unauthenticated pordal?
or is it only possible if the attacker got access to the admin GUI?

Admin GUI isnt accessable from external, and all SSL VPN Portals the Web-mode is disabled, but as the Web-mode-Login-PAge is still accessable... so is this a way to attack?

maybe everything is lost in translation at my point, and other people understand this CVE, but the reseller and technical service provider didnt understand the attack-possibilities too...

Can someone help me to learn something?:(

router login 192.168.l.l
2 REPLIES 2
dingjerry_FTNT

Hi @bevvet ,

 

As far as I understand it, no, the attacker has no access to your FortiGate via this vulnerability.

 

This vuln only attacks your FortiGate to be crashed, using API.

Regards,

Jerry
Hatibi
Staff
Staff

In this case the vulnerability is CVE-2024-46666 which will cause a Denial of Service.

You are vulnerable because an adversary/attacker can craft REST API requests that will make the FortiGate unresponsive and impact any endpoints using its services.

 

You should be concerned only if you have HTTP or HTTPD services enabled on any interfaces where API requests can be sent.

You can upgrade to the versions suggested in FG-IR-24-250 .Alternatively disable HTTP/HTTPS or use local-in policies by restricting on IPs allowed access.

 

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors