Scans for Fortinet FortiOS and the CVE-2024-21762 vulnerability, (Wed, Mar 20th)

Late last week, an exploit surfaced on GitHub for CVE-2024-21762 &#;x26;#;x5b;1&#;x26;#;x5d;. This vulnerability affects&#;x26;#;xc2;&#;x26;#;xa0;Fortinet&#;x26;#;39;s FortiOS. A patch was released on February 8th. Owners of affected devices had over a month to patch &#;x26;#;x5b;2&#;x26;#;x5d;. A few days prior to the GitHub post, the exploit was published on the Chinese QQ messaging network &#;x26;#;x5b;3&#;x26;#;x5d;

Continue reading Scans for Fortinet FortiOS and the CVE-2024-21762 vulnerability, (Wed, Mar 20th)

Posted in Uncategorized

Scans for Fortinet FortiOS and the CVE-2024-21762 vulnerability, (Wed, Mar 20th)

Late last week, an exploit surfaced on GitHub for CVE-2024-21762 &#;x26;#;x5b;1&#;x26;#;x5d;. This vulnerability affects&#;x26;#;xc2;&#;x26;#;xa0;Fortinet&#;x26;#;39;s FortiOS. A patch was released on February 8th. Owners of affected devices had over a month to patch &#;x26;#;x5b;2&#;x26;#;x5d;. A few days prior to the GitHub post, the exploit was published on the Chinese QQ messaging network &#;x26;#;x5b;3&#;x26;#;x5d;

Continue reading Scans for Fortinet FortiOS and the CVE-2024-21762 vulnerability, (Wed, Mar 20th)

Posted in Uncategorized

Attacker Hunting Firewalls, (Tue, Mar 19th)

Firewalls and other perimeter devices are a huge target these days. Ivanti, Forigate, Citrix, and others offer plenty of difficult-to-patch vulnerabilities for attackers to exploit. Ransomware actors and others are always on the lookout for new victims. However, being and access broker or ransomware peddler is challenging: The competition for freshly deployed vulnerable devices, or devices not patched for the latest greatest vulnerability, is immense. Your success in the ransomware or access broker ecosystem depends on having a consistently updated list of potential victims.

Continue reading Attacker Hunting Firewalls, (Tue, Mar 19th)

Posted in Uncategorized

5Ghoul Revisited: Three Months Later, (Fri, Mar 15th)

About three months ago, I wrote about the implications and impacts of 5Ghoul in a previous diary [1]. The 5Ghoul family of vulnerabilities could cause User Equipment (UEs) to be continuously exploited (e.g. dropping/freezing connections, which would require manual rebooting or downgrading a 5G connection to 4G) once they are connected to the malicious 5Ghoul gNodeB (gNB, or known as the base station in traditional cellular networks). Given the potential complexities in the realm of 5G mobile network modems used in a multitude of devices (such as mobile devices and 5G-enabled environments such as Industrial Internet-of-Things and IP cameras), I chose to give the situation a bit more time before revisiting the 5Ghoul vulnerability.

Patch updates have been made concerning the various products listed in Table 1 [1]. However, older models tend not to receive security updates due to the end of security patch support. Additionally, some vendors do not publicly make their firmware patch information available, which poses a challenge when ascertaining if affected products were patched. The updated Table 1 below shows the current patch status as of the publication of this diary entry:

Continue reading 5Ghoul Revisited: Three Months Later, (Fri, Mar 15th)

Posted in Uncategorized