USWEEKDAILY
  • News
  • Business
  • Crypto
  • Entertainment
  • Health
  • Technology
Reading: Fortinet confirms VPN vulnerability exploited in the wild
Share
Aa
USWEEKDAILYUSWEEKDAILY
  • Technology
Search
  • Home
  • Categories
    • Technology
  • More Foxiz
    • Blog Index
    • Forums
    • Complaint
    • Sitemap
Follow US
Made by ThemeRuby using the Foxiz theme. Powered by WordPress
USWEEKDAILY > Blog > Business > Fortinet confirms VPN vulnerability exploited in the wild
Business

Fortinet confirms VPN vulnerability exploited in the wild

By David Mitchell Last updated: October 9, 2024 3 Min Read
Share

Fortinet confirms VPN vulnerability exploited in the wild

A critical zero-day vulnerability in Fortinet’s SSL-VPN has been exploited in the wild in at least one instance.

Fortinet issued an advisory Monday detailing the heap-based buffer overflow flaw, tracked as CVE-2022-42475, affecting multiple versions of its FortiOS SSL-VPN. Ranked a 9.3 on the common vulnerability scoring system, Fortinet warned the critical flaw could allow a remote unauthenticated attacker to execute arbitrary code.

“Fortinet is aware of an instance where this vulnerability was exploited in the wild, and recommends immediately validating your systems against the following indicators of compromise,” Fortinet wrote in the advisory.

Patches are available, and Fortinet recommended upgrading to the latest versions as well as the unaffected earlier version of FortiOS. In an email to TechTarget Editorial, Fortinet said it also continues to monitor the situation.

Fortinet confirms VPN vulnerability exploited in the wild

While the company’s Product Security Incident Response team made the advisory publicly available Monday, it was not the first notification on the critical flaw. Olympe Cyberdefense, a France-based cyber threat intelligence vendor, released an alert Friday citing that a “new critical flaw, not yet made public” affected Fortinet SSL-VPN.

The alert, which was first reported Monday by TechTarget sister publication Le Mag IT, warned the zero-day vulnerability was easy to exploit and that attackers could gain full control of intended devices. Additionally, Olympe Cyberdefense recommended disabling VPN-SSL functionality if it’s not essential.

Olympe updated its alert once Fortinet confirmed the vulnerability and urged customers to patch.

In a statement sent to TechTarget Editorial, Claire Tills, senior researcher engineer at Tenable, noted the time gap between the Olympe’s initial disclosure and Fortinet’s advisory. “Three days after its initial public disclosure, Fortinet patched CVE-2022-42475 and confirmed it has been exploited in the wild,” Tills said.

“Fortinet SSL-VPNs have been a major target for years now — to the extent that the FBI and CISA issued a dedicated advisory to these flaws and their exploitation in 2021. Nation state actors are still known to exploit those legacy vulnerabilities in Fortinet SSL-VPNs. Given that this new vulnerability has already been exploited, organizations should patch CVE-2022-42475 immediately before it joins the ranks of other legacy VPN flaws.”

Attacks targeting VPNs have been on the rise, with multiple government warnings since 2020 when remote work increased amid the COVID-19 pandemic. In October, FortiOS faced another critical vulnerability that allowed attackers to bypass authentication and was exploited in the wild. Like Monday’s advisory, Fortinet was not the first to publicly disclose the flaw.

TAGGED: Fortinet confirms VPN vulnerability exploited in the wild

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

HOT NEWS

Self Love Clothing: Your Style and Boost with Trendy Clothing

News
October 9, 2024
Dr. Sreenath

Magical Journey of Dr. Sreenath: A Holistic Trainer’s Impact on Qatar

Dr. Sreenath, a name synonymous with holistic wellness in Qatar, has profoundly impacted the community…

March 25, 2025
Pelosi’s Husband

Attack on Pelosi’s Husband Spurs Concern Over Political Violence

An assault on Home Speaker Nancy Pelosi’s husband at their San Francisco house is spurring…

October 9, 2024
Obama

Obama barnstorms Midwest in play to salvage Democrats’ ‘Blue Wall’

Barack Obama did the unthinkable in his 2008 presidential bid, turning out voters in droves…

October 9, 2024

YOU MAY ALSO LIKE

Magical Journey of Dr. Sreenath: A Holistic Trainer’s Impact on Qatar

Dr. Sreenath, a name synonymous with holistic wellness in Qatar, has profoundly impacted the community through his innovative approach to…

Business
March 25, 2025

Resilience Shines Through: The Inspiring Journey of Dainnese Jackson, a Successful Author Who Rose from Humble Beginnings

Dainnese Jackson, born on May 14,1984  stands as a symbol of resilience. Raised in a low-income neighborhood in San Diego,…

Business
October 9, 2024

Unveiling Christel Khalil’s Net Worth in 2023: A Beginner’s Guide

Are you curious about the financial status of your favorite celebrities? If you've been following Christel Khalil's journey in the…

Business
October 9, 2024

Exploring Alanis Morissette’s Net Worth in 2023: A Beginner’s Guide

In the world of music, few artists have left as indelible a mark as Alanis Morissette. With her powerful voice,…

Business
October 9, 2024

USWeekDaily is a reputable magazine that delivers timely and comprehensive coverage of current affairs, lifestyle, entertainment, and culture in the United States.

  • Entertainment
  • Technology
  • Business
  • Health
  • News
  • Crypto
  • About
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
  • Remove News
  • Sponsored & Guest Post

USWEEKDAILY

The Business Centre, My Street Kingston, New York 12401 USA.
E-Mail: Contact@usweekdaily.com

Welcome Back!

Sign in to your account

Lost your password?