Fortinet FortiOS / FortiManager 2024 Zero-Days
Fortinet FortiOS / FortiManager 2024 Zero-Days とは何ですか?
Fortinet FortiOS / FortiManager 2024 Zero-DaysA 2024 series of pre-authentication vulnerabilities in Fortinet FortiOS, FortiProxy, FortiManager and the FortiGate SSL-VPN — including the FortiManager fgfmd flaw CVE-2024-47575 ('FortiJump') — exploited as zero-days by Chinese state-aligned actors.
Throughout 2024 Fortinet products were repeatedly targeted with pre-authentication zero-day vulnerabilities, especially in the FortiGate SSL-VPN service and in FortiManager's fgfmd protocol. The headline issue, CVE-2024-47575 ('FortiJump', disclosed October 2024, CVSS 9.8), is a missing-authentication flaw in FortiManager's fgfmd device-registration channel that lets an unauthenticated remote attacker register a malicious FortiGate, execute commands on the FortiManager, and pivot to manage every connected device. Mandiant attributed exploitation to UNC5820 (a China-nexus cluster) and observed compromise of dozens of FortiManagers before the patch and even some after. Other 2024 cases include CVE-2024-21762 (FortiOS SSL-VPN out-of-bound write, CVSS 9.6), CVE-2024-23113 (fgfmd format-string, CVSS 9.8), CVE-2024-55591 (Node.js websocket auth bypass in FortiOS), and CVE-2024-50603 (Aviatrix-style command injection). All were added to the CISA KEV catalog. The pattern reinforced that internet-exposed network-edge appliances remain a primary initial-access surface, especially for state-aligned actors building VPN-mediated footholds.
● 例
- 01
An MSSP's internet-exposed FortiManager is compromised via CVE-2024-47575 before its operator gets to patch; UNC5820 pushes config changes to dozens of customer FortiGates.
- 02
An enterprise enforces a 'no FortiGate management interface on the public internet' policy and configures FortiManager fgfmd to whitelist device certs after the FortiJump advisory.
● よくある質問
Fortinet FortiOS / FortiManager 2024 Zero-Days とは何ですか?
A 2024 series of pre-authentication vulnerabilities in Fortinet FortiOS, FortiProxy, FortiManager and the FortiGate SSL-VPN — including the FortiManager fgfmd flaw CVE-2024-47575 ('FortiJump') — exploited as zero-days by Chinese state-aligned actors. サイバーセキュリティの 脆弱性 カテゴリに属します。
Fortinet FortiOS / FortiManager 2024 Zero-Days とはどういう意味ですか?
A 2024 series of pre-authentication vulnerabilities in Fortinet FortiOS, FortiProxy, FortiManager and the FortiGate SSL-VPN — including the FortiManager fgfmd flaw CVE-2024-47575 ('FortiJump') — exploited as zero-days by Chinese state-aligned actors.
Fortinet FortiOS / FortiManager 2024 Zero-Days はどのように機能しますか?
Throughout 2024 Fortinet products were repeatedly targeted with pre-authentication zero-day vulnerabilities, especially in the FortiGate SSL-VPN service and in FortiManager's fgfmd protocol. The headline issue, CVE-2024-47575 ('FortiJump', disclosed October 2024, CVSS 9.8), is a missing-authentication flaw in FortiManager's fgfmd device-registration channel that lets an unauthenticated remote attacker register a malicious FortiGate, execute commands on the FortiManager, and pivot to manage every connected device. Mandiant attributed exploitation to UNC5820 (a China-nexus cluster) and observed compromise of dozens of FortiManagers before the patch and even some after. Other 2024 cases include CVE-2024-21762 (FortiOS SSL-VPN out-of-bound write, CVSS 9.6), CVE-2024-23113 (fgfmd format-string, CVSS 9.8), CVE-2024-55591 (Node.js websocket auth bypass in FortiOS), and CVE-2024-50603 (Aviatrix-style command injection). All were added to the CISA KEV catalog. The pattern reinforced that internet-exposed network-edge appliances remain a primary initial-access surface, especially for state-aligned actors building VPN-mediated footholds.
Fortinet FortiOS / FortiManager 2024 Zero-Days からどのように防御しますか?
Fortinet FortiOS / FortiManager 2024 Zero-Days に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。
Fortinet FortiOS / FortiManager 2024 Zero-Days の別名は何ですか?
一般的な別名: FortiJump, CVE-2024-47575, CVE-2024-21762。
● 関連用語
- vulnerabilities№ 1399
ゼロデイ脆弱性
発見または悪用された時点でベンダーが未認知、あるいはパッチがまだ存在しないセキュリティ上の欠陥。
- vulnerabilities№ 194
CISA Known Exploited Vulnerabilities (KEV) Catalog
A U.S. CISA-maintained list of CVEs with credible evidence of in-the-wild exploitation, paired with mandatory remediation deadlines for U.S. federal civilian agencies and widely used by enterprises as a priority signal.
- network-security№ 1339
VPN(仮想プライベートネットワーク)
公衆網上に暗号化・認証されたトンネルを構築し、あたかも専用網経由のように通信を扱う技術。
- network-security№ 1210
SSL VPN
TLS(歴史的には SSL)上で通信をトンネル化し、Web 標準ポート経由で専用 VPN プロトコルなしにリモートアクセスを可能にする VPN。
- attacks№ 1234
サプライチェーン攻撃
信頼されたサードパーティのソフトウェア・ハードウェア・サービス提供者を侵害し、その下流顧客に到達する攻撃。
- defense-ops№ 799
国家支援アクター
戦略・情報・軍事・経済目的のためにサイバー活動を行う、政府支援または政府関連の脅威アクター。