hi at all,
so, fortinet got some CVE's, nevermind... Every CVE i check if its attackable to our environment, ok...
but the FG-IR-24-250 one, i dont understand the concept...
Can someone explain this to me?
How could the unauthenticated attacker access the gui, or more like, how am i vulnerable?
Could the attacker attack is, if he get access to a gui? Like if he can access the SSL VPN Portal, he can use this attack unauthenticated pordal?
or is it only possible if the attacker got access to the admin GUI?
Admin GUI isnt accessable from external, and all SSL VPN Portals the Web-mode is disabled, but as the Web-mode-Login-PAge is still accessable... so is this a way to attack?
maybe everything is lost in translation at my point, and other people understand this CVE, but the reseller and technical service provider didnt understand the attack-possibilities too...
Can someone help me to learn something?:(
Hi @bevvet ,
As far as I understand it, no, the attacker has no access to your FortiGate via this vulnerability.
This vuln only attacks your FortiGate to be crashed, using API.
In this case the vulnerability is CVE-2024-46666 which will cause a Denial of Service.
You are vulnerable because an adversary/attacker can craft REST API requests that will make the FortiGate unresponsive and impact any endpoints using its services.
You should be concerned only if you have HTTP or HTTPD services enabled on any interfaces where API requests can be sent.
You can upgrade to the versions suggested in FG-IR-24-250 .Alternatively disable HTTP/HTTPS or use local-in policies by restricting on IPs allowed access.
User | Count |
---|---|
2098 | |
1184 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.